RFQ - 88310322Q00112 TeamMate Audit Software Licenses and Perpetual Maintenance.docx

DOCX document 63 KB Posted

Attached to
TeamMate+ Software Licenses for National Archives Federal contract opportunity
Solicitation number
88310322Q00112
Issued by
National Archives and Records Administration

View the file

Other files for this federal contract opportunity

Other files attached to TeamMate+ Software Licenses for National Archives, newest first.
File Type Posted
Justification and Approvals TeamMate.docx DOCX document
Notice of Intent - TeamMate.docx DOCX document

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

NARA 88310322Q00112 TeamMate+ Audit Software Licenses and Maintenance Support National Archives and Records Administration Office of the Chief Acquisition Officer 8601 Adelphi Road, Room 3340 College Park, MD 20740-6001

RFQ# 88310322Q00112

THIS IS A REQUEST FOR QUOTATION (THIS IS NOT AN ORDER) in accordance with FAR 13.106-1(b), Soliciting from a Single Source. The solicitation document and incorporated provisions and clauses are those in effect through Federal Acquisition Circular Number 2022-07 effective August 10, 2022.

This solicitation is for the acquisition of TeamMate+ Audit Software Licenses and Maintenance Support.

Complete and return one (1) copy of the quotation via e-mail by 12:00 PM ET on August 19, 2022 to:

Ms. Tyrice Buie (Contractor), Contract Specialist tyrice.buie@nara.gov

Please include the solicitation number in the subject line and allow one extra business day for delivery and receipt, as the email will need to pass through IT security.

This is a Request for Quotation and quotations furnished are not offers. This request does not commit the Government to pay any costs incurred in the preparation or submission of the quotation or to contract for supplies and/or services. Any representations and/or certifications attached to this Request for Quotation must be completed by the Contractor. This includes the submission, with the vendor’s quotation, of representations required by FAR provision 52.204-24, Representation Regarding Certain Telecommunications and Video Surveillance Services or Equipment and FAR provision 52.204-26, Covered Telecommunications Equipment or Services-Representation. FAR provision 52.212-3, Offeror Representations and Certifications - Commercial Products and Commercial Services (May 2022) - The offeror shall complete only paragraph (b) of this provision if the Offeror has completed the annual representations and certification electronically in the System for Award Management (SAM) accessed through https://www.sam.gov. If the Offeror has not completed the annual representations and certifications electronically, the Offeror shall complete only paragraphs (c) through (v)) of this provision.

The Contractor's quotation will be evaluated to determine whether or not it addresses the requirements of the RFQ. Furthermore, the Contractor’s responsibility will be evaluated prior to the issuance of any contract.

Enclosures:

Enclosure 1 – Schedule of Prices Enclosure 2 – Contract Administration Enclosure 3 – Additional NARA Terms and Conditions - (ADDENDA TO FAR CLAUSE 52.212-4) Enclosure 4 – FAR Clauses

ENCLOSURE 1

SCHEDULE OF PRICES

CLIN
DESCRIPTION
QTY
UNIT
FIRM-FIXED UNIT PRICE
TOTAL FIRM-FIXED PRICE
0001
Base Year: September 1, 2022 – August 31, 2023

TeamMate+ Audit Software Licenses and Perpetual Maintenance

EA

0002
Option Year I: September 1, 2023 – August 31, 2024

TeamMate+ Audit Software Licenses and Perpetual Maintenance

EA

0003
Option Year II: September 1, 2024 – August 31, 2025

TeamMate+ Audit Software Licenses and Perpetual Maintenance

EA

0004
Option Year III: September 1, 2025 – August 31, 2026

TeamMate+ Audit Software Licenses and Perpetual Maintenance

EA

0005
Option Year IV: September 1, 2026 – August 31, 2027

TeamMate+ Audit Software Licenses and Perpetual Maintenance

EA

TOTAL CONTRACT PRICE:

CLIN = Contract Line Item Number, QTY = Quantity

ENCLOSURE 2

CONTRACT ADMINISTRATION

I. GOVERNMENT CONTRACT ADMINISTRATION

A. This contract will be administered by:

National Archives and Records Administration Office of the Chief Acquisition Officer (Z) 8601 Adelphi Road, Room 3340 College Park, MD 20740-6001

B. Contract Specialist (CS):

See award document.

C. Contracting Officer (CO):

Any Z Warranted CO.

The Contracting Officer (CO) has the overall responsibility for the administration of this contract. Written communication to the Contract Specialist (CS) must reference the contract number and must be emailed or mailed with postage prepaid, to the above address.

The CO alone, without delegation, is authorized to take actions on behalf of the Government to amend, modify, or deviate from the contract terms, conditions requirements, specifications, details and/or delivery schedules; make final decisions on disputed deductions from contract for non-performance or unsatisfactory performance; terminate the contract for convenience or default; and issue final decisions regarding contract questions or matters under dispute. However, the CO may delegate certain other responsibilities to authorized representatives.

II. CONTRACTING OFFICER’S REPRESENTATIVE (COR) LEVEL 2:

a. COR: See award document

b. The individual named above is designated as the Contracting Officer’s Representative (COR) to assist the CO in the discharge of the CO’s responsibilities. The COR is responsible for monitoring, giving progress reports to the Contract Specialist (CS), and overall technical surveillance of services to be performed under this contract and should be contacted regarding questions or problems of a technical nature. In no event will any understanding or agreement, modification, change order, or other matter deviating from the terms of the contract between the Contractor and any person other than the CO be effective or binding upon the Government.

c. When, in the opinion of the Contractor, the COR requests effort outside the existing scope of the contract, the Contractor must promptly notify the CO in writing.

d. No action will be taken by the Contractor under such technical instruction unless the CO has issued a contractual change.

e. The responsibilities of the COR include, but are not limited to, the following:

(1) Serve as the point-of-contact through which the Contractor can relay questions or problems of a technical nature to the CS and the CO;

(2) Be responsible for the inspection and acceptance of the services performed and determining the adequacy of performance by the Contractor in accordance with the terms and conditions of this contract;

(3) Confer with representatives of the Contractor regarding any non-performance or unsatisfactory performance; following through to assure that all non-performance or unsatisfactory performance is performed/corrected or payment adjustment is recommended to the CS and the CO;

(4) Review and certify invoices in accordance with invoicing instructions of the contract. Maintain a file with copies of these documents;

(5) Review and evaluate Contractor’s cost estimates, furnish comments, and recommendations to the CS and the CO;

(6) Advise the CS of any performance problems and make recommendations for corrective action to correct performance issues;

(7) Furnish the CS with any requests for change, deviation, or waiver (whether generated by Government personnel or Contractor personnel), including all supporting paperwork in connection with such change, deviation, or waiver; and

8) Submit a written evaluation to the CS and the CO within 60 days of contract completion or annually on the anniversary for contract that include options. The evaluation must include:

(i) The quality and timeliness of the Contractor’s performance; and

(ii) A statement as to the uses made of any deliverables furnished by the Contractor.

III. ELECTRONIC INVOICING AND PAYMENT REQUIREMENTS – INVOICE PROCESSING PLATFORM (IPP) (January 2020)

(a) Payment request must be submitted electronically through the U.S. Department of the Treasury’s Invoice Processing Platform System (IPP).

(b) “Payment request” means any request for contract financing payment or invoice payment by the Contractor. To constitute a proper invoice, the payment request must comply with the requirements identified in the applicable Prompt Payment clause included in the contract, or the clause 52.212-4, Contract Terms and Conditions – Commercial Products and Commercial Services include commercial item contracts. The IPP website address is https://www.ipp.gov.

(c) Under this contract, the following documents are required to be submitted as an attachment to the IPP invoice. Invoice shall be submitted after Government’s acceptance of all deliverables. The invoice shall contain information required by FAR 52.212-4(g).

(d) Contractor invoice to include:

1. Award Number

2. CLIN/Item Number of deliverable

3. Description of deliverable

4. Price of deliverable

5. Quantity of deliverable

6. Date deliverable was provided to the Government for inspection, if applicable

7. Serial Number/Part Number, if applicable

(e) The Contractor must use the IPP website to register, access and use IPP for submitting requests for payment. Contractor assistance with enrollment can be obtained by contacting the IPP Customer Support Helpdesk by sending an email to IPPCustomerSupport@fiscal.treasury.gov or phone (866) 973-3131.

(f) If the Contractor is unable to comply with the requirement to use IPP for submitting invoices for payment, the Contractor must submit a waiver request in writing to the Contracting Officer with its proposal or quotation.

IV. FINAL PAYMENT

Before final NARA payment is made, the Contractor shall furnish to the Contracting Officer a written release of all claims against the Government arising by virtue of the contract, other than claims in stated amounts as may be specifically excluded by the Contractor from the operation of the release. If the Contractor's claim to amounts payable under the contract has been assigned under the Assignment of Claims Act of 1940, as amended (31 U.S.C. 203, 41 U.S.C. 15), a release may also be requested of the assignee. To ensure that all necessary adjustments for non-performance or unsatisfactory performance have been made and a release of claims has been submitted before the contract is closed out, the final NARA payment will be made in thirty (30) calendar days after receipt of a proper invoice, date of completion of performance, or receipt of release of claims by the Contracting Officer, whichever is later.

ENCLOSURE 3

ADDITIONAL NARA TERMS AND CONDITIONS

(Addenda to FAR clause 52.212-4)

I. SECURITY OF INFORMATION AND PROTECTION OF CONTROLLED UNCLASSIFIED INFORMATION, INCLUDING PERSONALLY IDENTIFIABLE INFORMATION (APRIL 2017)

(a) Applicability

This clause applies to all controlled unclassified information, which may include personally identifiable information, as defined in Section B, regardless of the medium in which it is found and includes paper records.

(b) Definitions. As used in this clause:

“Breach” means the loss of control, compromise, unauthorized disclosure, unauthorized acquisition, unauthorized access, or any similar situation where persons other than authorized users, and for other than authorized purpose, have access or potential access to personally identifiable information, in usable form whether physical or electronic.

“Controlled Unclassified Information” means information the Government creates or possesses, or that an entity creates or possesses for or on behalf of the Government, that a law, regulation, or Government-wide policy requires or permits an agency to handle using safeguarding or dissemination controls. However, CUI does not include classified information or information a non-executive branch entity possesses and maintains in its own systems that did not come from, or was not created or possessed by or for, an executive branch agency or an entity acting for an agency. Law, regulation, or Government-wide policy may require or permit safeguarding or dissemination controls in three ways: Requiring or permitting agencies to control or protect the information but providing no specific controls, which makes the information CUI Basic; requiring or permitting agencies to control or protect the information and providing specific controls for doing so, which makes the information CUI Specified; or requiring or permitting agencies to control the information and specifying only some of those controls, which makes the information CUI Specified, but with CUI Basic controls where the authority does not specify.

“Personally identifiable information (PII)” means any information that permits the identity of an individual to be directly or indirectly inferred, including any other information that is linked or linkable to that individual regardless of whether the individual is a citizen of the United States, legal permanent resident, or a visitor to the United States. Examples of PII include the following:

(1) Name.

(2) Date of birth.

(3) Mailing address.

(4) Telephone number.

(5) Social Security Number.

(6) Email address.

(7) Zip code.

(8) Account numbers.

(9) Certificate/license numbers.

(10) Vehicle identifiers including license plates.

(11) Uniform resource locators (URLs).

(12) Internet protocol addresses.

(13) Biometric identifiers (e.g., fingerprints).

(14) Photographic facial images.

(15) Any other unique identifying number or characteristic.

(16) Any information where it is reasonably foreseeable that the information will be linked with other information to identify the individual.

“Sensitive personally identifiable information (sensitive PII)” means a subset of PII, which if lost, compromised or disclosed without authorization, could result in substantial harm, embarrassment, inconvenience, or unfairness to an individual.

(1) Complete social security numbers, alien registration numbers (A-number) and biometric identifiers (such as fingerprint, voiceprint, or iris scan) are considered sensitive PII even if they are not coupled with additional PII.

(2) Additional examples include any grouping of information that contains an individual’s name or other unique identifier plus one or more of the following elements:

(i) Driver’s license number, passport number, or truncated social security number (such as last 4 digits);

(ii) Date of birth (month, day, and year);

(iii) Citizenship or immigration status;

(iv) Financial information such as account numbers or electronic funds transfer information;

(v) Medical information; and/or

(vi) System authentication information such as mother’s maiden name, account passwords or personal identification numbers.

(3) Other PII may be “sensitive” depending on its context, such as a list of employees with less than satisfactory performance ratings or an unlisted home address or phone number. In contrast, a business card or public telephone directory of agency employees contains PII but it is not sensitive.

(c) Data Security.

(1) The Contractor shall limit access to the data covered by this clause to those employees and subcontractor who require the information in order to perform their official duties under this contract.

(2) The Contractor employees, and subcontractors must physically or electronically secure CUI, which may include sensitive PII, when not in use and/or under the control of an authorized individual, and when in transit to prevent unauthorized access or loss.

(3) When CUI is no longer needed or required to be retained under applicable Government records retention policies, it must be destroyed in accordance with NIST 800-88 standards.

(4) The Contractor shall only use CUI obtained under this contract for purposes of the Contractor; it shall not be disclosed, released, disseminated, or published without the prior written consent of the Contracting Officer.

(5) If it is established elsewhere in this contract that information to be utilized under this contract, or a portion thereof, is subject to the Privacy Act, The Contractor shall follow the rules and procedures of disclosure set forth in the Privacy Act of 1974, 5 U.S.C. 552a, and implementing regulations and policies, with respect to systems of records determined to be subject to the Privacy Act.

(6) At expiration or termination of this contract, the Contractor shall turn over all CUI obtained under the Contractor that is in its possession.

(d) Systems Access. Work to be performed under this contract may require the handling of CUI, including PII. The Contractor shall provide the Government access to, and information regarding those systems handling CUI, including sensitive PII for the Government under the Contractor, when requested by the Government, as part of the Contractor’s responsibility to ensure compliance with security requirements, and shall otherwise cooperate with the Government in assuring compliance with such requirements. Government access shall include independent testing of controls, system penetration testing by the Government, Federal Information Security Management Act data reviews, and access by agency Inspectors General (IG) for IG reviews.

When requested by the NARA CO or COR or other NARA official as described herein, in connection with NARA’s efforts to ensure compliance with security requirements and to maintain and safeguard against threats and hazards to the security, confidentiality, integrity, and availability of NARA Information, Contractor shall provide NARA, including the NARA OIG, (1) access to any and all information and records, including electronic information, regarding a Covered Information System, and (2) physical access to Contractor's facilities, installations, systems, operations, documents, records, and databases. Such access may include independent validation testing of controls, system penetration testing, and FISMA data reviews by NARA or agents acting on behalf of NARA, and such access shall be provided within 72 hours of the request. Additionally, the Contractor shall cooperate with NARA’s efforts to ensure, maintain, and safeguard the security, confidentiality, integrity, and availability of NARA information.

(e) Systems Security.

(1) In performing its duties related to management, operation, and/or access of systems containing PII under this contract, the Contractor, its employees and subcontractors shall comply with all applicable security requirements and rules of conduct applicable to the agency’s systems as described in:

a) NARA Directive 1608 http://www.archives.gov/foia/directives/nara1608.pdf and

b) FedRAMP baseline controls for moderate IT systems.

(2) In addition, the use of Contractor-Owned laptops or other portable storage devices to process or store sensitive PII is prohibited under this contract until the Contractor provides, and the Contracting Officer, in coordination with the Senior Agency Official for Privacy (SAOP) or the SAOP’s designee, approves the Contractor’s written acknowledgment that the following requirements are met:

(i) Laptops and other portable storage devices must employ encryption that is NIST Federal Information Processing Standard (FIPS) 140-2 validated (or its successor) http://csrc.nist.gov/publications/PubsFIPS.html, and approved.

(ii) The Contractor has developed and implemented a process to ensure that security and other applications software are kept current.

(iii) Mobile computing devices utilize anti-virus software and a host-based firewall mechanism.

(iv) Removable media, such as hard drives, flash drives, devices with flash memory, CDs and floppy disks containing CUI, which may include sensitive PII shall not be removed from a Government facility unless they are encrypted using a NIST FIPS 140-2 or successor approved product.

(v) When no longer needed, all removable media, hard drives, and flash memory shall be destroyed in accordance with Government security requirements identified in NARA’s Media Protection Methodology.

(vi) The Contractor shall maintain an accurate inventory of devices used in the performance of this contract.

(3) All NARA information obtained under this contract shall be removed from Contractor-Owned information technology assets at the direction of the Contracting Officer or Contracting Officer’s Representative. Removal must be accomplished in accordance with standard FedRAMP controls for media protection in moderate IT systems and NIST 800-88 standards. Certification of data removal will be performed by the Contractor’s Project Manager and written notification confirming acknowledgment will be delivered to the Contracting Officer within 30 days of the direction to remove the information.

(4) Back up or mirrors of any systems or files containing CUI shall be treated in the same manner as the original data containing CUI, with the same protections and obligations.

(5) The Contractor shall require FIPS 140-2 (or successor) encryption of any sensitive PII when transmitted electronically across the Internet or other public works.

(f) Breach Notification to Government.

(1) The Contractor has been provided with: NARA Directive 1608, and is aware of its roles, responsibilities, and relationship with the Government in case of data breach.

(2) In the event of any actual or suspected breach of sensitive PII, the Contractor shall immediately, and in no event later than one hour of discovery, report the breach to the Contracting Officer, the COR, the Senior Agency Official for Privacy (currently NARA’s General Counsel garymstern@nara.gov) and the Chief Information Officer (only for IT requirements) in accordance with NARA Directive 1608.

(3) The Contractor is responsible for positively verifying that notification is received and acknowledged by appropriate Government parties identified in subparagraph (2) above.

(4) In the event of a confirmed, potential or suspected Security Breach, involving unauthorized exposure, loss of control, compromise, exfiltration, manipulation, disclosure, acquisition, or accessing of any Covered Information System or any NARA Information accessed by, retrievable from, processed by stored on, or transmitted within, to or from any such system, Contractor shall immediately (and in no event later than within 1 hour of discovery) report any Confirmed Breach to the NARA CO and the CO's Representative (''COR").

(5) NARA, at its sole discretion, may obtain, and Contractor will permit, the assistance of other federal agencies and/or third party contractors or firms to aid in response activities related to any security incident, PII or Security Breach. Additionally. NARA, at its sole discretion, may require Contractor to retain, at Contractor's expense, a Third Party Assessing Organization (3PAO) acceptable to NARA, with expertise in incident response, compromise assessment, and federal security control requirements, to conduct a thorough vulnerability and security assessment of all affected Information Systems.

(6) Any report submitted in accordance with paragraphs (1), (2) and (3) above, shall identify (I) both the Information Systems and NARA Information involved or at risk, including the type, amount, and level of sensitivity of the NARA Information and, if the NARA Information contains PII, the estimated number of unique instances of Pll, (2) all steps and processes being undertaken by Contractor to minimize, remedy, and/or investigate the Security Incident, (3) any and all other information as required by the USCERT Federal Incident Notification Guidelines, including the functional impact, information impact, impact to recoverability, threat vector, mitigation details, and all available incident details; and (4) any other information specifically requested by NARA. Contractor shall continue to provide written updates to the NARA CO regarding the status of the Security incident at least every three (3) calendar days until informed otherwise by the NARA CO.

(7) Response activities related to any security incident or PII or Security Breach undertaken by NARA, including activities undertaken by Contractor, other federal agencies, and any third-party contractors or firms at the request or direction of NARA, may include inspections, investigations, forensic reviews, data analyses and processing, and final determinations of responsibility for the Security Incident and/or liability for any additional response activities. Contractor shall be responsible for all costs and related resource a locations required for all such response activities related to any Security Incident or Breach, including the cost of any penetration testing.

(g) Personally Identifiable Information Notification Requirement

Contractor certifies that it has a security policy in place that contains procedures to promptly notify any individual whose Personally Identifiable Information ("PII") was, or is reasonably determined by NARA to have been, compromised. Any notification shall be coordinated with the NARA CO and shall not proceed until NARA has made a determination that notification would not impede a law enforcement investigation or jeopardize national security. The method and content of any notification by Contractor shall be coordinated with, and subject to the approval of, NARA. Contractor shall be responsible for taking corrective action consistent with NARA Data Breach Notification Procedures and as directed by the NARA CO, including all costs and expenses associated already covered by above clauses added in PII clause with such corrective action, which may include providing credit monitoring to any individuals whose PII was actually or potentially compromised. All determinations regarding whether and when to notify individuals and/or federal agencies potentially affected by a Security Incident, Breach, or PII Breach will be made by NARA senior officials at NARA’s discretion.

(h) Flowdown of security requirements to subcontractors.

(1) The Contractor shall incorporate the substance of this clause, its terms and requirements including this paragraph (g), in all subcontracts under this contract, and require written subcontractor acknowledgement of same.

(2) Violation by a subcontractor of any provision set forth in this clause will be attributed to the Contractor.

II. CONFIDENTIAL INFORMATION

(a) Confidential information is any information that, if subject to unauthorized access, modification, loss, or misuse could adversely affect the national interest, the conduct of Federal programs, or the privacy of individuals, but has not been specifically authorized under criteria established by an Executive Order or an Act of Congress to be kept secret in the interest of national defense or foreign policy. Confidential information also includes proprietary data and information for which other restrictions on access apply.

(b) The Contracting Officer and the Contractor may, by mutual consent, identify elsewhere in this contract specific information and/or categories of information which the Government will furnish to the Contractor or that the Contractor is expected to generate which is confidential. Similarly, the Contracting Officer and the Contractor may, by mutual consent, identify such confidential information from time to time during the performance of the contract. Failure to agree will be settled pursuant to the “Disputes” clause.

(c) While in the course of performance of this contract, the Contractor may have access to confidential information and communications, including but not limited to Personally Identifiable Information (PII). Confidential information may be contained in printed material or on electronic media. The Contractor will preserve the confidentiality of all such information and communications and agrees not to disclose, release, disseminate, or publish any such information or communications for any purposes whatsoever without the prior approval of the Contracting Officer. Failure to comply with the provisions of this paragraph will be grounds for Termination for Cause and the Contractor may be liable for damages. This provision shall survive the expiration or termination of the period of performance of this contract.

(d) If it is established elsewhere in this contract that information to be utilized under this contract, or a portion thereof, is subject to the Privacy Act, the Contractor will follow the rules and procedures of disclosure set forth in the Privacy Act of 1974, 5 U.S.C. 552a, and implementing regulations and policies, with respect to systems of records determined to be subject to the Privacy Act.

(e) During the course of the performance of this contract, the Contractor may have access to and use of data and information which may be considered proprietary by other contractors, or which may otherwise be of such a nature that its dissemination or use, other than in performance of this contract, would be adverse to the interest of NARA and these other contractors.

(f) Except as may be otherwise agreed to with these other contractors, the Contractor agrees that it will not use, disclose or reproduce proprietary data and information belonging to these other contractors other than as required in the performance of this contract; provided, however, that nothing herein shall be construed as: (1) precluding the use of any such data or information independently acquired by the Contractor without such limitation; or (2) prohibiting an agreement at no cost to NARA between the Contractor and these contractors which provides for greater rights to the Contractor.

(g) When considering a request to disclose, release, disseminate, or publish confidential information, the Contracting Officer will consult with appropriate program and legal officials.

(h) At the discretion of the Contracting Officer, the Contractor’s employees may be required to sign a non-disclosure agreement prior to performing any work under this contract.

(i) The terms of this paragraph apply to all Contractor employees, subcontractors, and consultants and must be incorporated into any subcontract.

III. RECORDS MANAGEMENT OBLIGATIONS

A. Applicability This clause applies to all Contactors whose employees create, work with, or otherwise handle Federal records, as defined in Section B, regardless of the medium in which the record exists.

B. Definitions “Federal record” as defined in 44 U.S.C. § 3301, includes all recorded information, regardless of form or characteristics, made or received by a Federal agency under Federal law or in connection with the transaction of public business and preserved or appropriate for preservation by that agency or its legitimate successor as evidence of the organization, functions, policies, decisions, procedures, operations, or other activities of the United States Government or because of the informational value of data in them.

The term Federal record:

1. includes NARA records.

2. does not include personal materials.

3. applies to records created, received, or maintained by Contractors pursuant to their NARA contract.

4. may include deliverables and documentation associated with deliverables.

C. Requirements

1. Contractor shall comply with all applicable records management laws and regulations, as well as National Archives and Records Administration (NARA) records policies, including but not limited to the Federal Records Act (44 U.S.C. chs. 21, 29, 31, 33), NARA regulations at 36 CFR Chapter XII Subchapter B, and those policies associated with the safeguarding of records covered by the Privacy Act of 1974 (5 U.S.C. 552a). These policies include the preservation of all records, regardless of form or characteristics, mode of transmission, or state of completion.

2. In accordance with 36 CFR 1222.32, all data created for Government use and delivered to, or falling under the legal control of, the Government are Federal records subject to the provisions of 44 U.S.C. chapters 21, 29, 31, and 33, the Freedom of Information Act (FOIA) (5 U.S.C. 552), as amended, and the Privacy Act of 1974 (5 U.S.C. 552a), as amended and must be managed and scheduled for disposition only as permitted by statute or regulation.

3. In accordance with 36 CFR 1222.32, Contractor shall maintain all records created for Government use or created in the course of performing the contract and/or delivered to,

4. or under the legal control of the Government and must be managed in accordance with Federal law. Electronic records and associated metadata must be accompanied by sufficient technical documentation to permit understanding and use of the records and data.

5. NARA and its contractors are responsible for preventing the alienation or unauthorized destruction of records, including all forms of mutilation. Records may not be removed from the legal custody of NARA or destroyed except for in accordance with the provisions of the agency records schedules and with the written concurrence of the Head of the Contracting Activity. Willful and unlawful destruction, damage or alienation of Federal records is subject to the fines and penalties imposed by 18 U.S.C. 2701. In the event of any unlawful or accidental removal, defacing, alteration, or destruction of records, Contractor must report to NARA. The agency must report promptly to NARA in accordance with 36 CFR 1230.

6. The Contractor shall immediately notify the appropriate Contracting Officer upon discovery of any inadvertent or unauthorized disclosures of information, data, documentary materials, records or equipment. Disclosure of non-public information is limited to authorized personnel with a need-to-know as described in the [contract vehicle]. The Contractor shall ensure that the appropriate personnel, administrative, technical, and physical safeguards are established to ensure the security and confidentiality of this information, data, documentary material, records and/or equipment is properly protected. The Contractor shall not remove material from Government facilities or systems, or facilities or systems operated or maintained on the Government’s behalf, without the express written permission of the Head of the Contracting Activity. When information, data, documentary material, records and/or equipment is no longer required, it shall be returned to NARA’s control or the Contractor must hold it until otherwise directed. Items returned to the Government shall be hand carried, mailed, emailed, or securely electronically transmitted to the Contracting Officer or address prescribed in the contract. Destruction of records is EXPRESSLY PROHIBITED unless in accordance with Paragraph (4).

7. The Contractor is required to obtain the Contracting Officer's approval prior to engaging in any contractual relationship (sub-contractor) in support of this contract requiring the disclosure of information, documentary material and/or records generated under, or relating to, contracts. The Contractor (and any sub-contractor) is required to abide by Government and NARA guidance for protecting sensitive, proprietary information, classified, and controlled unclassified information.

8. The Contractor shall only use Government IT equipment for purposes specifically tied to or authorized by the contract and in accordance with NARA policy.

9. The Contractor shall not create or maintain any records containing any non-public NARA information that are not specifically tied to or authorized by the contract.

10. The Contractor shall not retain, use, sell, or disseminate copies of any deliverable that contains information covered by the Privacy Act of 1974 or that which is generally protected from public disclosure by an exemption to the Freedom of Information Act.

11. NARA owns the rights to all data and records produced as part of this contract. All deliverables under the contract are the property of the U.S. Government for which NARA shall have unlimited rights to use, dispose of, or disclose such data contained therein as it determines to be in the public interest. Any Contractor rights in the data or deliverables must be identified as required by FAR 52.227-11 through FAR 52.227-20.

12. Training. All Contractor employees assigned to this contract who create, work with, or otherwise handle records are required to take NARA-provided records management training. The Contractor is responsible for confirming training has been completed according to agency policies, including initial training and any annual or refresher training.

D. Flowdown of requirements to subcontractors

1.The Contractor shall incorporate the substance of this clause, its terms and requirements including this paragraph, in all subcontracts under this contract, and require written subcontractor acknowledgment of same.
2.Violation by a subcontractor of any provision set forth in this clause will be attributed to the contract.
IV.INTERNET PROTOCOL (AUG 2016)

The Contractor shall ensure that all systems, including hardware, software, firmware, and/or network components developed, procured, or acquired in support and/or performance of this contract using the Internet Protocol are formatted in accordance with commercial standards of Internet Protocol (IP) version 6 (IPv6) as set forth in the USGv6 Profile (NIST Special Publication 800-119). In addition, all products or systems using the Internet Protocol shall maintain operability with both Internet Protocol (IP) IPv4 and IPv6.

V. GOVERNING LAW (continuation of Schedule of Supplies and Services above):

Federal law and regulations, including the Federal Acquisition Regulations (FAR), shall govern this Contract/Order. Commercial license agreements may be made a part of this Contract/Order but only if both parties expressly make them an addendum hereto, as permitted by FAR 12.212. If the commercial license agreement is not made an addendum, it shall not apply, govern, be a part of or have any effect whatsoever on the Contract/Order; this includes, but is not limited to, any agreement embedded in the computer software (clickwrap), any agreement that is otherwise delivered with or provided to the Government with the commercial computer software or documentation (shrinkwrap), or any other license agreement otherwise referred to in any document. If a commercial license agreement is made an addendum, only those provisions addressing data rights regarding the Government’s use, duplication and disclosure of data (e.g., restricted computer software) are included and made a part of this Contract/Order, and only to the extent that those provisions are not duplicative or inconsistent with Federal law, Federal regulation, the incorporated FAR clauses and the provisions of this Contract/Order; those provisions in the commercial license agreement that do not address data rights regarding the Government’s use, duplication and disclosure of data shall not be included or made a part of the Contract/Order. Federal law and regulation including, without limitation, the Contract Disputes Act (41 U.S.C. § 7101 et seq.), the Anti-Deficiency Act (31 U.S.C. § 1341 et seq.), the Competition in Contracting Act (41 U.S.C. § 3301 et seq.), the Prompt Payment Act (31 U.S.C. §3901 et seq.), Contracts for Data Processing or Maintenance (38 USC § 5725), and FAR clauses 52.212-4, 52.227-14, 52.227-19 shall supersede, control, and render ineffective any inconsistent, conflicting, or duplicative provision in any commercial license agreement. In the event of conflict between this clause and any provision in the Contract/Order or the commercial license agreement or elsewhere, the terms of this clause shall prevail. The Contractor shall deliver to the Government all data first produced under this Contract/Order with unlimited rights as defined by FAR 52.227-14. Claims of patent or copyright infringement brought against the Government as a party shall be defended by the U.S. Department of Justice (DOJ in accordance with 28 U.S.C. § 516; at the discretion of DOJ, the Contractor may be allowed reasonable participation in the defense of the litigation. Any additional changes to the Contract/Order must be made by contract/order modification (Standard Form 30) and shall only be made by a warranted Contracting Officer. Nothing in this Contract/Order or any commercial license agreement shall be construed as a waiver of sovereign immunity.

VI. SOFTWARE LICENSE, MAINTENANCE AND TECHNICAL SUPPORT:

1. Definitions.

(a) Licensee. The term “licensee” shall mean the U.S. Department of Veterans Affairs (“VA”) and is synonymous with “Government.”

(b) Licensor. The term “licensor” shall mean the contractor having the necessary license or ownership rights to deliver license, software maintenance and support of the computer software being acquired. The term “contractor” is the party identified in Block 17a on the SF1449. If the contractor is a reseller and not the Licensor, the contractor remains responsible for performance under this order.

(c) Software. The term “software” shall mean the licensed computer software product(s) cited in the Schedule of Supplies/Services.

(d) Maintenance. The term “maintenance” is the process of enhancing and optimizing software, as well as remedying defects. It shall include all new fixes, patches, releases, updates, versions and upgrades, as further defined below.

(e) Technical Support. The term “technical support” refers to the range of services providing assistance for the software via the telephone, email, a website or otherwise.

(f) Release or Update. The term “release” or “update” are terms that refer to a revision of software that contains defect corrections, minor enhancements or improvements of the software’s functionality. This is usually designated by a change in the number to the right of the decimal point (e.g., from Version 5.3 to 5.4). An example of an update is the addition of new hardware.

(g) Version or Upgrade. The term “version” or “upgrade” are terms that refer to a revision of software that contains new or improved functionality. This is usually designated by a change in the number to the left of the decimal point (e.g., from Version 5.4 to 6).

2. Software License

(a) Unless otherwise stated in the Schedule of Supplies/Services, the Performance Work Statement or Product Description, the software license provided to the Government is a perpetual, nonexclusive license to use the software.

(b) The Government may use the software in a networked environment.

(c) Any dispute regarding the license grant or usage limitations shall be resolved in accordance with the Disputes Clause incorporated in FAR 52.212-4(d).

(d) All limitations of software usage are expressly stated in the Schedule of Supplies/Services and the Performance Work Statement/Product Description.

3. Software Maintenance and Technical Support

(a) If the Government desires to continue software maintenance and support beyond the period of performance identified in this contract or order, the Government will issue a separate contract or order for maintenance and support. Conversely, if a contract or order for continuing software maintenance and technical support is not received the contractor is neither authorized nor permitted to renew any of the previously furnished services.

(b) The contractor shall provide software support services, which includes periodic updates, enhancements and corrections to the software, and reasonable technical support, all of which are customarily provided by the contractor to its commercial customers so as to cause the software to perform according to its specifications, documentation or demonstrated claims.

(c) Any telephone support provided by contractor shall be at no additional cost.

(d) The contractor shall provide all maintenance services in a timely manner in accordance with the contractor’s customary practice or as defined in the Performance Work Statement/Product Description. However, prolonged delay (exceeding 2 business days) in resolving software problems will be noted in the Government’s various past performance records on the contractor (e.g., www.ppirs.gov).

(e) If the Government allows the maintenance and support to lapse and subsequently wishes to reinstate it, any reinstatement fee charged shall not exceed the amounts that would have been charged if the Government had not allowed the subscription to lapse.

4. Disabling Software Code. The Government requires delivery of computer software that does not contain any code that will, upon the occurrence or the nonoccurrence of any event, disable the software. Such code includes but is not limited to a computer virus, restrictive key, node lock, time-out or other function, whether implemented by electronic, mechanical, or other means, which limits or hinders the use or access to any computer software based on residency on a specific hardware configuration, frequency of duration of use, or other limiting criteria. If any such disabling code is present, the contractor agrees to indemnify the Government for all damages suffered as a result of a disabling caused by such code, and the contractor agrees to remove such code upon the Government’s request at no extra cost to the Government. Inability of the contractor to remove the disabling software code will be considered an inexcusable delay and a material breach of contract, and the Government may exercise its right to terminate for cause. In addition, the Government is permitted to remove the code as it deems appropriate and charge the Contractor for consideration for the time and effort expended in removing the code.

5. Manuals and Publications. Upon Government request, the contractor shall furnish the most current version of the user manual and publications for all products/services provided under this contract or order at no cost.

ENCLOSURE 4

FAR CLAUSES

I. FAR 52.212-4 -- Contract Terms and Conditions -- Commercial Products and Commercial Services (Nov 2021) II. FAR 52.212-5 -- Contract Terms and Conditions Required to Implement Statutes or Executive Orders -- Commercial Products and Commercial Services (May 2022)

(a) The Contractor shall comply with the following Federal Acquisition Regulation (FAR) clauses, which are incorporated in this contract by reference, to implement provisions of law or Executive orders applicable to acquisitions of commercial products and commercial services:

(1) 52.203-19, Prohibition on Requiring Certain Internal Confidentiality Agreements or Statements (JAN 2017) (section 743 of Division E, Title VII, of the Consolidated and Further Continuing Appropriations Act, 2015 (Pub. L. 113-235) and its successor provisions in subsequent appropriations acts (and as extended in continuing resolutions)).

(2) 52.204-23, Prohibition on Contracting for Hardware, Software, and Services Developed or Provided by Kaspersky Lab and Other Covered Entities (NOV 2021) (Section 1634 of Pub. L. 115-91).

(3) 52.204-25, Prohibition on Contracting for Certain Telecommunications and Video Surveillance Services or Equipment. (NOV 2021) (Section 889(a)(1)(A) of Pub. L. 115-232).

(4) 52.209-10, Prohibition on Contracting with Inverted Domestic Corporations (NOV 2015).

(5) 52.233-3, Protest After Award (AUG 1996) ( 31 U.S.C. 3553).

(6) 52.233-4, Applicable Law for Breach of Contract Claim (OCT 2004) (Public Laws 108-77 and 108-78 ( 19 U.S.C. 3805 note)).

(b) The Contractor shall comply with the FAR clauses in this paragraph (b) that the Contracting Officer has indicated as being incorporated in this contract by reference to implement provisions of law or Executive orders applicable to acquisitions of commercial products and commercial services:

__ (1) 52.203-6, Restrictions on Subcontractor Sales to the Government (JUN 2020), with Alternate I (NOV 2021) ( 41 U.S.C. 4704 and 10 U.S.C. 2402).

__ (2) 52.203-13, Contractor Code of Business Ethics and Conduct (NOV 2021) ( 41 U.S.C. 3509)).

__ (3) 52.203-15, Whistleblower Protections under the American Recovery and Reinvestment Act of 2009 (JUN 2010) (Section 1553 of Pub. L. 111-5). (Applies to contracts funded by the American Recovery and Reinvestment Act of 2009.)

(4) 52.204-10, Reporting Executive Compensation and First-Tier Subcontract Awards (JUN 2020) (Pub. L. 109-282) ( 31 U.S.C. 6101 note).

__ (5) [Reserved].

__ (6) 52.204-14, Service Contract Reporting Requirements (OCT 2016) (Pub. L. 111-117, section 743 of Div. C).

__ (7) 52.204-15, Service Contract Reporting Requirements for Indefinite-Delivery Contracts (OCT 2016) (Pub. L. 111-117, section 743 of Div. C).

(8) 52.209-6, Protecting the Government’s Interest When Subcontracting with Contractors Debarred, Suspended, or Proposed for Debarment. (NOV 2021) ( 31 U.S.C. 6101 note).

__ (9) 52.209-9, Updates of Publicly Available Information Regarding Responsibility Matters (OCT 2018) ( 41 U.S.C. 2313).

__ (10) [Reserved].

__ (11) 52.219-3, Notice of HUBZone Set-Aside or Sole-Source Award (SEP 2021) ( 15 U.S.C. 657a).

__ (12) 52.219-4, Notice of Price Evaluation Preference for HUBZone Small Business Concerns (SEP 2021) (if the offeror elects to waive the preference, it shall so indicate in its offer) ( 15 U.S.C. 657a).

__ (13) [Reserved] __ (14) (i) 52.219-6, Notice of Total Small Business Set-Aside (NOV 2020) ( 15 U.S.C. 644).

__ (ii) Alternate I (MAR 2020) of 52.219-6.

__ (15) (i) 52.219-7, Notice of Partial Small Business Set-Aside (NOV 2020) ( 15 U.S.C. 644).

__ (ii) Alternate I (MAR 2020) of 52.219-7.

__ (16) 52.219-8, Utilization of Small Business Concerns (OCT 2018) ( 15 U.S.C. 637(d)(2) and (3)).

__ (17) (i) 52.219-9, Small Business Subcontracting Plan (NOV 2021) ( 15 U.S.C. 637(d)(4)).

__ (ii) Alternate I (NOV 2016) of 52.219-9.

__ (iii) Alternate II (NOV 2016) of 52.219-9.

__ (iv) Alternate III (JUN 2020) of 52.219-9.

__ (v) Alternate IV (SEP 2021) of 52.219-9.

__ (18) (i) 52.219-13, Notice of Set-Aside of Orders (MAR 2020) ( 15 U.S.C. 644(r)).

__ (ii) Alternate I (MAR 2020) of 52.219-13.

__ (19) 52.219-14, Limitations on Subcontracting (SEP 2021) ( 15 U.S.C. 637s).

__ (20) 52.219-16, Liquidated Damages—Subcontracting Plan (SEP 2021) ( 15 U.S.C. 637(d)(4)(F)(i)).

__ (21) 52.219-27, Notice of Service-Disabled Veteran-Owned Small Business Set-Aside (SEP 2021) ( 15 U.S.C. 657f).

__ (22) (i) 52.219-28, Post Award Small Business Program Rerepresentation (SEP 2021) ( 15 U.S.C. 632(a)(2)).

__ (ii) Alternate I (MAR 2020) of 52.219-28.

__ (23) 52.219-29, Notice of Set-Aside for, or Sole-Source Award to, Economically Disadvantaged Women-Owned Small Business Concerns (SEP 2021) ( 15 U.S.C. 637(m)).

__ (24) 52.219-30, Notice of Set-Aside for, or Sole-Source Award to, Women-Owned Small Business Concerns Eligible Under the Women-Owned Small Business Program (SEP 2021) ( 15 U.S.C. 637(m)).

__ (25) 52.219-32, Orders Issued Directly Under Small Business Reserves (MAR 2020) ( 15 U.S.C. 644(r)).

__ (26) 52.219-33, Nonmanufacturer Rule (SEP 2021) ( 15U.S.C. 637(a)(17)).

(27) 52.222-3, Convict Labor (JUN 2003) (E.O.11755).

(28) 52.222-19, Child Labor-Cooperation with…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .