About this file

This is a request for quotes (RFQ) from the National Institute of Allergy and Infectious Diseases (NIAID), a division of the National Institutes of Health (NIH), seeking to acquire a commercial-off-the-shelf electronic common technical document (eCTD) and electronic document management system (EDMS). The RFQ will be awarded as a single firm fixed price purchase order for an initial twelve-month base period and four additional twelve-month option periods. Quotes will be evaluated based on experience and configuration, product demonstration, technical submission, and price through a two-phase advisory down select process. The deadline for Phase I responses is August 3, 2021, with Phase II submissions due within ten business days of advisory guidance. Product demonstrations are scheduled August 23-26, 2021. The associated North American Industry Classification System code is 541512 with a small business size standard of $30 million. The purchase order will be awarded based on best value to the government.

View the file

Other files for this federal contract opportunity

Other files attached to Electronic Common Technical Document (eCTD) Publishing and Reviewing Software, newest first.
File Type Posted
QA_PHASE II_NIAID eCTD_RFQ2076690.pdf PDF
QA_PHASE I_NIAID eCTD_RFQ2076690.pdf PDF
Attachment 4_Pricing Sheet_RFQ2076690.xlsx XLSX spreadsheet
Attachment 1_SOW_NIAID eCTD_RFQ2076690.pdf PDF
Attachment 2_HHS Subcontracting Plan Template_RFQ2076690.doc DOC document
Attachment 3_Full Text Provisions and Clauses_RFQ2076690.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

eCTD for NIAID Request for Quote

Solicitation ID: RFQ-2076690

REQUEST FOR QUOTE (RFQ)

Solicitation Number RFQ-2076690

Title:

Electronic Common Technical Document (eCTD) Publishing and Reviewing Software

Conducted under Federal Acquisition Regulation (FAR) Parts 12, 13, and Subpart 13.5

Issued by:

Department of Health and Human Services (HHS), National Institutes of

Health (NIH), National Institute of Allergy and Infectious Diseases (NIAID)

Released 7/20/2021

RFQ TABLE OF CONTENTS

PART 1 – THE SCHEDULE

SECTION A – COMBINED SYNOPSIS/SOLICITATION

SECTION B - SUPPLIES OR SERVICES AND PRICES

SECTION C - DESCRIPTION/SPECIFICATIONS/WORK STATEMENT

SECTION D - PACKAGING, MARKING AND SHIPPING

SECTION E - INSPECTION AND ACCEPTANCE

SECTION F - DELIVERIES OR PERFORMANCE

SECTION G – PURCHASE ORDER ADMINISTRATION DATA

SECTION H - SPECIAL PURCHASE ORDER REQUIREMENTS

ARTICLE H.1. OPTION PROVISION

ARTICLE H.2. SUBCONTRACTING PROVISIONS

ARTICLE H.3. INFORMATION SECURITY AND/OR PHYSICAL ACCESS SECURITY

ARTICLE H.4. GOVERNMENT INFORMATION PROCESSED ON GOCO OR COCO SYSTEMS

ARTICLE H.5. CLOUD SERVICES

ARTICLE H.6. PHYSICAL ACCESS TO GOVERNMENT CONTROLLED FACILITIES

ARTICLE H.7. ELECTRONIC AND INFORMATION TECHNOLOGY ACCESSIBILITY NOTICE

PART II – PURCHASE ORDER CLAUSES

PART III - LIST OF DOCUMENTS, EXHIBITS AND OTHER ATTACHMENTS

SECTION J - LIST OF ATTACHMENTS

PART IV - REPRESENTATIONS AND INSTRUCTIONS

SECTION K - REPRESENTATIONS, CERTIFICATIONS AND OTHER STATEMENTS OF QUOTERS

SECTION L - INSTRUCTIONS, CONDITIONS, AND NOTICES TO QUOTERS

1. GENERAL INFORMATION

a. AWARD ON INITIAL RESPONSES

b. EXCHANGES WITH BEST SUITED QUOTER

c. TYPE OF CONTRACT AND NUMBER OF AWARDS

d. COMMITMENT OF PUBLIC FUNDS

e. COMMUNICATIONS PRIOR TO PURCHASE ORDER AWARD

f. SPECIAL NOTICE TO QUOTERS

g. SPECIAL NOTICE AND AGREEMENT REGARDING SOFTWARE EULA/TOS

2. INSTRUCTIONS TO QUOTERS

a. GENERAL INSTRUCTIONS

b. QUOTER QUESTIONS

c. QUOTE SUBMISSION DEADLINE

d. ADDITIONAL INFO

e. QUOTE CONTENT

f. VOLUME TABLE

g. VOLUME 1 – EXPERIENCE AND LEVEL OF CONFIGURATION (PHASE I)

h. VOLUME 2 – TECHNICAL SUBMISSION (PHASE II)

i. VOLUME 3 – PRICE (PHASE II)

j. PRODUCT DEMONSTRATION (PHASE II)

SECTION M - EVALUATION FACTORS FOR AWARD

a. BEST VALUE EVALUATION

b. GENERAL

c. EVALUATION OF OPTIONS

d. EVALUATION FACTORS

PART I – THE SCHEDULE

SECTION A

COMBINED SYNOPSIS/SOLICITATION

This notice is a combined synopsis/solicitation for commercial items prepared in accordance with the format in Federal Acquisition Regulation (FAR) Subpart 12.6 “Streamlined Procedures for Evaluation and Solicitation for Commercial Items,” as applicable, and as supplemented with additional information included in this notice. This announcement constitutes the only solicitation; quotes are being requested and a written solicitation document will not be issued. The National Institute of Allergy and Infectious Diseases (NIAID) is seeking to acquire a commercial-off-the-shelf (COTS) Electronic Common Technical Document (eCTD) and Electronic Document Management System (EDMS) system. Submit quotes on RFQ-2076690.

This solicitation is a request for quotes (RFQ). The solicitation documents and incorporated provisions and clauses are those in effect through Federal Acquisition Circular (FAC) 2021-06 effective July 12, 2021. The associated North American Industry Classification System (NAICS) code for this procurement is 541512 Computer System Design Services with a small business size standard of $30.0 Million. This acquisition will be awarded under Simplified Acquisition Procedures, FAR Subpart 13.5 – Simplified Procedures for Certain Commercial Items and is not a total small business set aside. The Government anticipates awarding a single Firm Fixed Priced purchase order for a twelve-month base period and four (4) twelve-month option periods.

The Government will award one firm fixed price purchase order resulting from this solicitation to the vendor whose quotation conforms to the solicitation and represents the best value to the government.

Evaluations will be performed in accordance with the evaluation criteria outlined in Sections L and M in the RFQ. The quoter will be evaluated in accordance with the following factors: Factor 1: Experience and Level of Configuration; Factor 2: Demonstration; Factor 3: Technical Submission; and Factor 4:

Price through a two-phase advisory down select process. Phase I will be based on Factor 1: Experience and Level of Configuration, and Phase II will be based on Factor 2: Product Demonstration, Factor 3:

Technical Submission and Factor 4: Price.

If you have questions regarding Phase I, please submit inquires immediately, but no later than Thursday, July 29, 2021 5:00 PM EST. The Government will issue an amendment to the RFQ responding to questions, if needed. The deadline for quoters to submit Phase I responses and questions regarding Phase II is 5:00 pm EST on August 3, 2021. Phase I submissions and all questions shall be sent to Tamara McDermott at tamara.mcdermott@nih.gov. The due date for Phase II submissions will be ten (10) business days from receiving the advisory guidance from the Contracting Officer Tamara McDermott. Product demonstrations will be scheduled August 23, 2021 through August 26, 2021.

In accordance with 52.212-1, Instructions to Offerors, paragraph (f), quotes received after the established closing date will be viewed as late, and therefore not considered. Contractors must follow mailto:tamara.mcdermott@nih.gov the instructions including 52.212-1 and the supplemental instructions. Quoter must be registered in the System for Award Management (SAM) prior to award of a purchase order. Quoters may access SAM at https://sam.gov. Clause 52.212-4 - Contract Terms and Conditions, applies to this solicitation.

See section L of this RFQ for further instructions. Quotes shall be good for 90 calendar days from the date of submission.

SECTION B

SUPPLIES OR SERVICES AND PRICES

Article B.1 STATEMENT OF NEED

The purpose of this requirement is to obtain a commercial-off-the-shelf (COTS) Electronic Common Technical Document (eCTD) and Electronic Document Management System (EDMS) system for the National Institutes of Health (NIH) National Institute of Allergy and Infectious Diseases (NIAID). The eCTD and EDMS software must be offered as a Software-as-a-Service (SaaS) and/or managed cloud solution.

Specifically, NIAID is seeking:

• A COTS eCTD compilation, publishing, validation, and review system that can scale to support multiple divisions within NIAID with appropriate security and access controls to prevent access to submissions and information between divisions

• A COTS EDMS system that integrates with the eCTD system, can scale to support multiple divisions within NIAID, and employs appropriate security and access controls to prevent access to documents and information between divisions

• Professional services to configure, deploy, train, validate, and support NIAID’s use and adoption of the new eCTD and EDMS systems

• Technical support services to support the migration of existing eCTD submission and their full lifecycles from the existing eCTD publishing system

• Ongoing system support including maintaining compliance with changing regulatory requirements, software upgrades, computer systems validation, and mitigation of security

Article B.2 CURRENT SYSTEM

To prepare for a U.S. Food and Drug Administration (FDA) mandate on eCTD submission of Commercial Investigational New Drug (IND) applications, NIAID constructed and deployed a validated COTS eCTD system and validated EDMS system (OpenText Content Server 10.5) which became operational in September 2016, with the first submission to FDA transmitted on May 12, 2017. The system is in-use today by NIAID divisions and external partners (e.g. Contract Research Organizations) that support them. NIAID currently produces approximately 500 sequences per year and expects that number to continue growing.

https://sam.gov/

The current system is used for the storage of final documents for submissions in the EDMS, compilation and publishing of eCTD INDs and Drug Master Files, eCTD validation of submissions, archive of transmitted submission packages in the EDMS, and the review of eCTD applications. NIAID’s current eCTD solution consists of On Premise installations of Parexel Liquent InSight 6.2 eCTD and OpenText Content Server 10.5 EDMS.

ARTICLE B.3. PRICES

The following represents the Government’s proposed CLIN structure. The final purchase order will contain the price provisions agreed upon by the Government and the Quoter.

CLIN Type Description Quantity/Unit Annual Price 0001 FFP BASE YEAR – NIAID eCTD 1 Lump Sum $ 0002 FFP BASE YEAR – Implementation

Technical Services 1 Lump Sum $

0003 FFP BASE YEAR (Optional Task) Data Migration

1 Lump Sum $

1001 FFP OPTION YEAR 1 – NIAID eCTD 1 Lump Sum $ 2001 FFP OPTION YEAR 2 – NIAID eCTD 1 Lump Sum $ 3001 FFP OPTION YEAR 3 – NIAID eCTD 1 Lump Sum $ 4001 FFP OPTION YEAR 4 – NIAID eCTD 1 Lump Sum $

TOTAL QUOTED PRICE (includes all options): $_________________

SECTION C

DESCRIPTION/SPECIFICATIONS/WORK STATEMENT

Article C.1 STATEMENT OF WORK (SOW)

Independently and not as an agent of the Government, the Contractor shall be required to furnish all the necessary services, qualified personnel, material, equipment, and facilities, not other provided by the Government, as needed to perform the Statement of Work, dated June 17, 2021, attached hereto and made a part of this Solicitation (See Section J - LIST OF ATTACHMENTS).

Article C.2. REPORTING REQUIREMENTS

All reports required herein shall be submitted in electronic format and shall be compliant with Section 508 of the Rehabilitation Act of 1973. Additional information about test documents for Section 508 compliance, including guidance and specific checklists, by application can be found at:

http://www.hhs.gov/web/508/index.html under "Making Files Accessible.”

http://www.hhs.gov/web/508/index.html http://www.hhs.gov/web/508/index.html

a. Other Reports/Deliverables

1. HHS SECURITY AND PRIVACY LANGUAGE FOR INFORMATION AND IT PROCUREMENTS

INFORMATION AND/OR PHYSICAL SECURITY

A. Security Assessment and Authorization (SA&A)- A valid authority to operate (ATO) certifies that the Contractor's information system meets the purchase order's requirements to protect the agency data. If the system under this purchase order does not have a valid ATO, the Contractor (and/or any subcontractor) shall work with the agency and supply the deliverables required to complete the ATO within the specified timeline(s) within three (3) months after purchase order award. The Contractor shall conduct the SA&A requirements in accordance with HHS IS2P, NIST SP 800-37, Guide for Applying the Risk Management Framework to Federal Information Systems: A Security Life Cycle Approach (latest revision).

For an existing ATO, Contracting Officer Representative must make a determination if the existing ATO provides appropriate safeguards or if an additional ATO is required for the performance of the purchase order and state as such.

NIH acceptance of the ATO does not alleviate the Contractor's responsibility to ensure the system security and privacy controls are implemented and operating effectively.

B. SA&A Package Deliverables - The Contractor (and/or any subcontractor) shall provide an SA&A package within 30 days of purchase order award to the CO and/or COR. The following SA&A deliverables are required to complete the SA&A package.

• System Security Plan (SSP) - due within 30 days after purchase order award. The SSP shall comply with the NIST SP 800-18, Guide for Developing Security Plans for Federal Information Systems, the Federal Information Processing Standard (FIPS) 200, Recommended Security Controls for Federal Information Systems, and NIST SP 800-53, Security and Privacy Controls for Federal Information Systems and Organizations applicable baseline requirements, and other applicable NIST guidance as well as HHS and NIH policies and other guidance. The SSP shall be consistent with and detail the approach to IT security contained in the Contractor's bid or proposal that resulted in the award of this purchase order. The SSP shall provide an overview of the system environment and security requirements to protect the information system as well as describe all applicable security controls in place or planned for meeting those requirements. It should provide a structured process for planning adequate, cost-effective security protection for a system. The Contractor shall update the SSP at least annually thereafter.

• Security Assessment Plan/Report (SAP/SAR) - due 30 days after the purchase order award. The security assessment shall be conducted by the assessor and be consistent with NIST SP 800-53A, NIST SP 800-30, and HHS and NIH policies. The assessor will document the assessment results in the SAR.

The NIH should determine which security control baseline applies and then make a determination on the appropriateness/necessity of obtaining an independent assessment. Assessments of controls can be performed by contractor, government, or third parties, with third party verification considered the strongest. If independent assessment is required, include statement below.

Thereafter, the Contractor, in coordination with the NIH shall conduct/assist in the assessment of the security controls and update the SAR at least annually.

• Independent Assessment - due 90 days after the purchase order award. The Contractor (and/or subcontractor) shall have an independent third-party validate the security and privacy controls in place for the system(s). The independent third party shall review and analyze the Security Authorization package, and report on technical, operational, and management level deficiencies as outlined in NIST SP 800-53. The Contractor shall address all "high" deficiencies before submitting the package to the Government for acceptance. All remaining deficiencies must be documented in a system Plan of Actions and Milestones (POA&M).

• POA&M - due 30 days after purchase order award. The POA&M shall be documented consistent with the HHS Standard for Plan of Action and Milestones and NIH policies. All high-risk weaknesses must be mitigated within 30 days and all medium weaknesses must be mitigated within 60 days from the date the weaknesses are formally identified and documented. The NIH will determine the risk rating of vulnerabilities. Identified risks stemming from deficiencies related to the security control baseline implementation, assessment, continuous monitoring, vulnerability scanning, and other security reviews and sources, as documented in the SAR, shall be documented and tracked by the Contractor for mitigation in the POA&M document. Depending on the severity of the risks, NIH may require designated POAM weaknesses to be remediated before an ATO is issued. Thereafter, the POA&M shall be updated at least quarterly.

• Contingency Plan and Contingency Plan Test - due 60 days after purchase order award.

The Contingency Plan must be developed in accordance with NIST SP 800-34, Contingency Planning Guide for Federal Information Systems, and be consistent with HHS and NIH policies. Upon acceptance by the System Owner, the Contractor, in coordination with the System Owner, shall test the Contingency Plan and prepare a Contingency Plan Test Report that includes the test results, lessons learned and any action items that need to be addressed. Thereafter, the Contractor shall update and test the Contingency Plan at least annually.

• E-Authentication Questionnaire - The contractor (and/or any subcontractor) shall collaborate with government personnel to ensure that an E-Authentication Threshold Analysis (E-auth TA) is completed to determine if a full E-Authentication Risk Assessment (E-auth RA) is necessary. System documentation developed for a system using E-auth TA/E-auth RA methods shall follow OMB 04-04 and NIST SP 800-63, Rev. 2, Electronic Authentication Guidelines.

Based on the level of assurance determined by the E-Auth, the Contractor (and/or subcontractor) must ensure appropriate authentication to the system, including remote authentication, is in-place in accordance with the assurance level determined by the E- Auth (when required) in accordance with HHS policies.

C. POSITION SENSITIVITY DESIGNATIONS

All Contractor (and/or any subcontractor) employees must obtain a background investigation commensurate with their position sensitivity designation that complies with Parts 1400 and; 731 and 732 of Title 5, Code of Federal Regulations (CFR). To determine the designation, the Position Designation Tool (PDT) discussion is found at:

https://www.ors.od.nih.gov/ser/dpsac/resources/Pages/investigation-requirements-for-your-position.aspx and the link to access the tool is found at: https://pdt.nbis.mil/ .

The following position sensitivity designation levels apply to this solicitation/purchase order:

[ ] Tier 5: Critical Sensitive and Special Sensitive National Security, including Top Secret, SCI, and “Q” access eligibility.

[ ] Tier 5SR: Reinvestigation.

[ ] Tier 4: High Risk Public Trust (HRPT).

[ ] Tier 4SR: Reinvestigation.

[ ] Tier 3: Non-Critical Sensitive, National Security, including Secret and “L” access eligibility.

[ ] Tier 3SR: Reinvestigation.

[X] Tier 2S with Subject Interview: Moderate Risk Public Trust (MRPT).

[X] Tier 2SR: Reinvestigation.

[ ] Tier 1: Low Risk, Non-Sensitive, including HSPD-12 Credentialing.

HOMELAND SECURITY PRESIDENTIAL DIRECTIVE (HSPD)-12 Roster-

a. The Contractor (and/or any subcontractor) shall submit a roster by name, position, e-mail address, phone number and responsibility, of all staff working under this acquisition where the Contractor will develop, have the ability to access, or host and/or maintain a government information system(s). The roster shall be submitted to the COR and/or CO within fourteen (14) calendar days after the effective date of this purchase order. Any revisions to the roster as a result of staffing changes shall be submitted within seven (7) https://www.ors.od.nih.gov/ser/dpsac/resources/Pages/investigation-requirements-for-your-position.aspx https://www.ors.od.nih.gov/ser/dpsac/resources/Pages/investigation-requirements-for-your-position.aspx https://pdt.nbis.mil/ calendar days of the change. The COR will notify the Contractor of the appropriate level of investigation required for each staff member. An electronic template, "Roster of Employees Requiring Suitability Investigations," is available for Contractor use at:

https://ocio.nih.gov/aboutus/publicinfosecurity/acquisition/Documents/SuitabilityRoster_1 0-15-12.xlsx.

b. If the Contractor is filling a new position, the Contractor shall provide a position description and the Government will determine the appropriate suitability level. Upon receipt of the Government's notification of applicable Suitability Investigations required, the Contractor shall complete and submit the required forms within 30 days of the notification.

c. Upon receipt of the Government's notification of applicable Suitability Investigations required, the Contractor shall complete and submit the required forms within 30 days of the notification.

d. The Contractor shall notify the Contracting Officer in advance when any new personnel, who are subject to a background check/investigation, will work under the purchase order and if they have previously been the subject of national agency checks or background investigations.

e. All Contractor and subcontractor employees shall comply with the conditions established for their designated position sensitivity level prior to performing any work under this purchase order. Contractors may begin work after the fingerprint check has been completed.

f. Investigations are expensive and may delay performance, regardless of the outcome of the investigation. Delays associated with rejections and consequent re-investigations may not be excusable in accordance with the FAR clause, Excusable Delays - see FAR 52.249-14.

Accordingly, the Contractor shall ensure that any additional employees whose names it submits for work under this purchase order have a reasonable chance for approval.

g. Typically, the Government investigates personnel at no cost to the Contractor. However, multiple investigations for the same position may, at the Contracting Officer's discretion, justify reduction(s) in the purchase order price of no more that the cost of the additional investigation(s).

h. The Contractor shall include language similar to this "HHS Controlled Facilities and Information Systems Security" language in all subcontracts that require subcontractor personnel to have the same frequency and duration of (1) physical access to an HHS-controlled facility; (2) logical access to an HHS-controlled information system; (3) access to sensitive HHS data/information, whether in an HHS-controlled information system or in hard copy; or (4) any combination of circumstances (1) through (3).

i. The Contractor shall direct inquiries, including requests for forms and assistance, to the Contracting Officer or designee.

j. Within 7 calendar days after the Government's final acceptance of the work under this purchase order, or upon termination of the purchase order, the Contractor shall return all identification badges to the Contracting Officer or designee.

https://ocio.nih.gov/aboutus/publicinfosecurity/acquisition/Documents/SuitabilityRoster_10-15-12.xlsx https://ocio.nih.gov/aboutus/publicinfosecurity/acquisition/Documents/SuitabilityRoster_10-15-12.xlsx https://ocio.nih.gov/aboutus/publicinfosecurity/acquisition/Documents/SuitabilityRoster_10-15-12.xlsx

PURCHASE ORDER INITIATION AND EXPIRATION

1. General Security Requirements- The Contractor (and/or any subcontractor) shall comply with information security and privacy requirements, Enterprise Performance Life Cycle (EPLC) processes, HHS Enterprise Architecture requirements to ensure information is appropriately protected from initiation to expiration of the purchase order. All information systems development or enhancement tasks supported by the Contractor shall follow the HHS EPLC framework and methodology.

HHS EA requirements are located at: https://www.hhs.gov/sites/default/files/eplc-policy-dec-2016.pdf and NIH EA requirements are located at:

https://ocio.nih.gov/PM/Pages/EPLC.aspx .

2. System Documentation- Contractors (and/or any subcontractors) must follow and adhere to NIST SP 800-160, Systems Security Engineering: Considerations for a Multidisciplinary Approach in the Engineering of Trustworthy Secure Systems, at a minimum, for system development and provide system documentation at designated intervals (specifically, at the expiration of the purchase order) within the EPLC that require artifact review and approval.

3. Sanitization of Government Files and Information- As part of purchase order closeout and at expiration of the purchase order, the Contractor (and/or any subcontractor) shall provide all required documentation in accordance with the NIH Media Sanitization and Disposal Policy to the CO and/or COR to certify that, at the government's direction, all electronic and paper records are appropriately disposed of and all devices and media are sanitized in accordance with NIST SP 800-88, Guidelines for Media Sanitization.

4. Notification- The Contractor (and/or any subcontractor) shall notify the CO and/or COR and system ISSO within fifteen days before an employee stops working under this purchase order.

5. Contractor Responsibilities Upon Physical Completion of the Purchase Order- The contractor (and/or any subcontractors) shall return all government information and IT resources (i.e., government information in non-government-owned systems, media, and backup systems) acquired during the term of this purchase order to the CO and/or COR.

Additionally, the Contractor shall provide a certification that all government information has been properly sanitized and purged from Contractor-owned systems, including backup systems and media used during purchase order performance, in accordance with HHS and/or NIH policies.

6. The Contractor (and/or any subcontractor) shall perform and document the actions identified in the NIH Contractor Employee Separation Checklist https://ocio.nih.gov/aboutus/publicinfosecurity/acquisition/Documents/Emp-sep-checklist.pdf when an employee terminates work under this purchase order within 2 days of the employee's exit from the purchase order. All documentation shall be made available to the CO and/or COR upon request.

7. Contractor Non-Disclosure Agreement (NDA)- Each Contractor (and/or any subcontractor) employee having access to non-public government information under this purchase order shall complete the NIH non-disclosure agreement https://www.hhs.gov/sites/default/files/eplc-policy-dec-2016.pdf https://www.hhs.gov/sites/default/files/eplc-policy-dec-2016.pdf https://ocio.nih.gov/PM/Pages/EPLC.aspx https://ocio.nih.gov/aboutus/publicinfosecurity/acquisition/Documents/Emp-sep-checklist.pdf https://ocio.nih.gov/aboutus/publicinfosecurity/acquisition/Documents/Emp-sep-checklist.pdf https://ocio.nih.gov/aboutus/publicinfosecurity/acquisition/Documents/Emp-sep-checklist.pdf https://ocio.nih.gov/aboutus/publicinfosecurity/acquisition/Documents/Nondisclosure.pdf

, as applicable. A copy of each signed and witnessed NDA shall be submitted to the Contracting Officer (CO) and/or CO Representative (COR) prior to performing any work under this acquisition.

8. Vulnerability Scanning Reports- The Contractor shall report the results of the required monthly special vulnerability scans no later than 10 days following the end of each reporting period. If required monthly, this report may be included as part of the Technical Progress Report. Otherwise, this report shall be submitted under a separate cover on monthly basis.

9. Government Access for Security Assessment- In addition to the Inspection Clause in the purchase order, the Contractor (and/or any subcontractor) shall afford the Government access to the Contractor's facilities, installations, operations, documentation, information systems, and personnel used in performance of this purchase order to the extent required to carry out a program of security assessment (to include vulnerability testing), investigation, and audit to safeguard against threats and hazards to the confidentiality, integrity, and availability of federal data or to the protection of information systems operated on behalf of HHS, including but are not limited to:

a. At any tier handling or accessing information, consent to and allow the Government, or an independent third party working at the Government's direction, without notice at any time during a weekday during regular business hours contractor local time, to access contractor and subcontractor installations, facilities, infrastructure, data centers, equipment (including but not limited to all servers, computing devices, and portable media), operations, documentation (whether in electronic, paper, or other forms), databases, and personnel which are used in performance of the purchase order.

The Government includes but is not limited to the U.S. Department of Justice, U.S.

Government Accountability Office, and the HHS Office of the Inspector General (OIG).

The purpose of the access is to facilitate performance inspections and reviews, security and compliance audits, and law enforcement investigations. For security audits, the audit may include but not be limited to such items as buffer overflows, open ports, unnecessary services, lack of user input filtering, cross site scripting vulnerabilities, SQL injection vulnerabilities, and any other known vulnerabilities.

b. At any tier handling or accessing protected information, fully cooperate with all audits, inspections, investigations, forensic analysis, or other reviews or requirements needed to carry out requirements presented in applicable law or policy. Beyond providing access, full cooperation also includes, but is not limited to, disclosure to investigators of information sufficient to identify the nature and extent of any criminal or fraudulent activity and the individuals responsible for that activity. It includes timely and complete production of requested data, metadata, information, and records relevant to any inspection, audit, investigation, or review, and making employees of the contractor available for interview by inspectors, auditors, and investigators upon request. Full cooperation also includes allowing the Government to make reproductions or copies of information and equipment, including, if necessary, collecting a machine or system image capture.

c. Segregate Government protected information and metadata on the handling of Government protected information from other information. Commingling of information is prohibited. Inspectors, auditors, and investigators will not be precluded from having access to the sought information if sought information is commingled with other information.

d. Cooperate with inspections, audits, investigations, and reviews.

2. Section 508 Annual Report

The contractor shall submit an annual Section 508 report in accordance with the schedule set forth by the Contracting Officer (CO)/Contracting Officer’s Representative (COR). The Section 508 Report Template and Instructions for completing the report are available at:

http://www.hhs.gov/web/508/contracting/technology/vendors.html under "Vendor Information and Documents."

SECTION D

PACKAGING, MARKING AND SHIPPING

All deliverables required under this purchase order shall be packaged, marked and shipped in accordance with Government specifications. At a minimum, all deliverables shall be marked with the purchase order number and Contractor name. The Contractor shall guarantee that all required materials shall be delivered in immediate usable and acceptable condition.

SECTION E

INSPECTION AND ACCEPANCE

a. The Contracting Officer or the duly authorized representative will perform inspection and acceptance of materials and services to be provided.

b. For the purpose of this SECTION, ____To be specified at time of award_____ is the authorized representative of the Contracting Officer.

c. Inspection and acceptance will be performed at:

Business Process and Information Management Branch (BPIMB) Office of Cyber Infrastructure and Computational Biology (OCICB)

OSMO/OD/NIAID/NIH

5601 Fishers Lane http://www.hhs.gov/web/508/contracting/technology/vendors.html http://www.hhs.gov/web/508/contracting/technology/vendors.html

Rockville, MD 20852

d. Acceptance may be presumed unless otherwise indicated in writing by the Contracting Officer or the duly authorized representative within 30 days of receipt.

SECTION F

DELIVERIES OR PERFORMANCE

Article F.1 PERIOD OF PERFORMANCE

a. The period of performance of this order is from date of award for 365 days; currently estimated September 22, 2021 through September 21, 2022.

b. If the Government exercises its options pursuant to the OPTION PROVISION Article in Section H of this purchase order, the period of performance is estimated to increase as listed below:

Option Option Period Option Year 1 September 22, 2022 – September 21, 2023 Option Year 2 September 22, 2023 – September 21, 2024 Option Year 3 September 22, 2024 – September 21, 2025 Option Year 4 September 22, 2025 – September 21, 2026

Option periods may be exercised in accordance with FAR Clause 52.217-9 entitled “Option to Extend the Term of the Contract.”

ARTICLE F.2. DELIVERIES

Satisfactory performance of the final purchase order shall be deemed to occur upon performance of the work described in the Statement of Work Article in SECTION C of this purchase order and upon delivery and acceptance by the Contracting Officer, or the duly authorized representative, of the items identified in the Statement of Work in accordance with the applicable delivery schedule.

SECTION G

PURCHASE ORDER ADMINISTRATION DATA

ARTICLE G.1. CONTRACTING OFFICER REPRESENTATIVE (COR)

The following Contracting Officer Representative (COR) will represent the Government for the purpose of this purchase order:

To be specified at time of award

The COR is responsible for: (1) monitoring the Contractor's technical progress, including the surveillance and assessment of performance and recommending to the Contracting Officer changes in requirements; (2) interpreting the statement of work and any other technical performance requirements; (3) performing technical evaluation as required; (4) performing technical inspections and acceptances required by this purchase order; and (5) assisting in the resolution of technical problems encountered during performance.

The Contracting Officer is the only person with authority to act as agent of the Government under this purchase order. Only the Contracting Officer has authority to: (1) direct or negotiate any changes in the statement of work; (2) modify or extend the period of performance; (3) change the delivery schedule;

(4) authorize reimbursement to the Contractor for any costs incurred during the performance of this purchase order; (5) otherwise change any terms and conditions of this purchase order; or (6) sign written licensing agreements. Any signed agreement shall be incorporated by reference in Section K of the purchase order.

The Government may unilaterally change its COR designation.

ARTICLE G.2. KEY PERSONNEL, HHSAR 352.237-75 (December 2015)

The key personnel specified in this purchase order are considered to be essential to work performance.

At least 30 days prior to the contractor voluntarily diverting any of the specified individuals to other programs or contracts the Contractor shall notify the Contracting Officer and shall submit a justification for the diversion or replacement and a request to replace the individual. The request must identify the proposed replacement and provide an explanation of how the replacement's skills, experience, and credentials meet or exceed the requirements of the purchase order (including, when applicable, Human Subjects Testing requirements). If the employee of the contractor is terminated for cause or separates from the contractor voluntarily with less than thirty days’ notice, the Contractor shall provide the maximum notice practicable under the circumstances. The Contractor shall not divert, replace, or announce any such change to key personnel without the written consent of the Contracting Officer. The purchase order will be modified to add or delete key personnel as necessary to reflect the agreement of the parties.

(End of clause)

The following individual(s) is/are considered to be essential to the work being performed hereunder:

Name Title Project Manager

ARTICLE G.3. INVOICE SUBMISSION

Invoice and Payment Provisions

The following clause is applicable to all Purchase Orders, Task or Delivery Orders, and Blanket Purchase Agreement (BPA) Calls: Prompt Payment (Jan 2017) FAR 52.232-25. Highlights of this clause and NIH implementation requirements follow:

I. Invoice Requirements A. An invoice is the Contractor's bill or written request for payment under the contract for supplies delivered or services performed. A proper invoice is an "Original" which must include the items listed in subdivisions 1 through 12, below, in addition to the requirements of FAR 32.9. If the invoice does not comply with these requirements, the Contractor will be notified of the defect within 7 days after the date the designated billing office received the invoice (3 days for meat, meat food products, or fish, and 5 days for perishable agricultural commodities, dairy products, edible fats or oils) with a statement of the reasons why it is not a proper invoice. (See exceptions under II., below.) Untimely notification will be taken into account in the computation of any interest penalty owed the Contractor.

1. Vendor/Contractor: Name, Address, Point of Contact for the invoice (Name, title, telephone number, e-mail and mailing address of point of contact).

2. Remit-to address (Name and complete mailing address to send payment).

3. Remittance name must match exactly with name on original order/contract. If the

Remittance name differs from the Legal Business Name, then both names must appear on the invoice.

4. Invoice date.

5. Unique invoice #s for all invoices per vendor regardless of site.

6. NBS document number formats must be included for awards created in the NBS: Contract

Number; Purchase Order Number; Task or Delivery Order Number and Source Award Number (e.g., Indefinite Delivery Contract number; General Services Administration number); or, BPA Call Number and BPA Parent Award Number.

7. Data Universal Numbering System (DUNS) or DUNS + 4 as registered in the Central Contractor Registration (CCR).

8. Federal Taxpayer Identification Number (TIN). In those exceptional cases where a contractor does not have a DUNS number or TIN, a Vendor Identification Number (VIN) must be referenced on the invoice. The VIN is the number that appears after the contractor’s name on the face page of the award document.

9. Identify that payment is to be made using a three-way match.

10. Description of supplies/services that match the description on the award, by line billed.*

11. Freight or delivery charge must be billed as shown on the award. If it is included in the item price do not bill it separately. If identified in the award as a separate line item, it must be billed separately.

12. Quantity, Unit of Measure, Unit Price, Extended Price of supplies delivered or services performed, as applicable, and that match the line items specified in the award.*

NOTE: If your invoice must differ from the line items on the award, please contact the Contracting Officer before submitting the invoice. A modification to the order or contract may be needed before the invoice can be submitted and paid.

B. Shipping costs will be reimbursed only if authorized by the Contract/Purchase Order. If authorized, shipping costs must be itemized. Where shipping costs exceed $100, the invoice must be supported by a bill of lading or a paid carrier's receipt.

C. The Contractor shall submit invoice to the National Institutes of Health (NIH)/Office of Financial Management (OFM) via email at invoicing@nih.gov with a copy to the approving official, as directed below. The Contractor must follow step-by-step instructions as stated in the NIH/OFM Electronic Invoicing Instructions for NIH Contractors/Vendors, which is included as an attachment on the website at https://oamp.od.nih.gov/DGS/DGS-workform-information/attachment-files. The invoice shall be transmitted as an attachment via email to the address listed above in one of the following formats: Word, or Adobe Portable Document Format (PDF). The Contractor must submit only one invoice per email. Do not submit supporting documentation (e.g., receipts, time sheets, vendor invoices, etc.) with your invoice unless specified elsewhere in the purchase order/contract or requested by the Contracting Officer.

The Contractor shall submit a copy of the electronic invoice to the following:

Approving Official: Contracting Officer Tamara McDermott tamara.mcdermott@nih.gov

Contracting Officer’s Representative

TBD

For inquiries regarding the status of invoices, contact OFM Customer Service via email at ofm_customer_service@incontactemail.com or via phone at 301-496-6088. To send your inquiries via other available communication methods refer to the OFM Customer Service website at https://ofm.od.nih.gov/Pages/Customer-Service.aspx.

Note: The OFM Customer Service is open Eastern Standard Time Monday – Friday from 8:30 a.m. to 5:00 p.m. and is closed between 12:00 p.m. to 1:00 p.m.

II. Invoice Payment

A. Except as indicated in paragraph B., below, the due date for making invoice payments by the designated payment office shall be the later of the following two events:

https://ofm.od.nih.gov/Pages/Home.aspx https://ofm.od.nih.gov/Pages/Home.aspx mailto:invoicing@nih.gov https://oamp.od.nih.gov/DGS/DGS-workform-information/attachment-files https://oamp.od.nih.gov/DGS/DGS-workform-information/attachment-files https://oamp.od.nih.gov/DGS/DGS-workform-information/attachment-files mailto:tamara.mcdermott@nih.gov mailto:OFM%20Customer%20Service mailto:ofm_customer_service@incontactemail.com https://ofm.od.nih.gov/Pages/Customer-Service.aspx

1. The 30th day after the designated billing office has received a proper invoice.

2. The 30th day after Government acceptance of supplies delivered or services performed.

B. The due date for making invoice payments for meat and meat food products, perishable agricultural commodities, dairy products, and edible fats or oils, shall be in accordance with the Prompt Payment Act, as amended.

III. Interest Penalties

A. An interest penalty shall be paid automatically, if payment is not made by the due date and the conditions listed below are met, if applicable.

1. A proper invoice was received by the designated billing office.

2. A receiving report or other Government documentation authorizing payment was processed and there was no disagreement over quantity, quality, or contractor compliance with a term or condition.

3. In the case of a final invoice for any balance of funds due the contractor for supplies delivered or services performed, the amount was not subject to further settlement actions between the Government and the Contractor.

B. Determination of interest and penalties due will be made in accordance with the provisions of the Prompt Payment Act, as amended, the Contract Disputes Act, and regulations issued by the Office of Management and Budget.

ARTICLE G.4. PROVIDING ACCELERATED PAYMENT TO SMALL BUSINESS SUBCONTRACTORS, FAR

52.232-40 (December 2013)

a. Upon receipt of accelerated payments from the Government, the Contractor shall make accelerated payments to its small business subcontractors under this contract, to the maximum extent practicable and prior to when such payment is otherwise required under the applicable contract or subcontract, after receipt of a proper invoice and all other required documentation from the small business subcontractor.

b. The acceleration of payments under this clause does not provide any new rights under the prompt Payment Act.

c. Include the substance of this clause, include this paragraph c, in all subcontracts with small business concerns, including subcontracts with small business concerns for the acquisition of commercial items.

(End of clause)

ARTICLE G.5. POST AWARD EVALUATION OF CONTRACTOR PERFORMANCE

a. Contractor Performance Evaluations Interim and Final evaluations of Contractor performance will be prepared on this purchase order in accordance with FAR Subpart 42.15. The Final performance evaluation will be prepared at the time of completion of work. In addition to the Final evaluation, Interim evaluation(s) will be prepared Annually as follows on [Insert Dates].

Interim and Final evaluations will be provided to the Contractor as soon as practicable after completion of the evaluation. The Contractor will be permitted thirty days to review the document and to submit additional information or a rebutting statement. If agreement cannot be reached between the parties, the matter will be referred to an individual one level above the Contracting Officer, whose decision will be final.

Copies of the evaluations, Contractor responses, and review comments, if any, will be retained as part of the purchase order file, and may be used to support future award decisions.

b. Electronic Access to Contractor Performance Evaluations Contractors may access evaluations through a secure Web site for review and comment at the following address:

http://www.cpars.gov

SECTION H

SPECIAL PURCHASE ORDER REQUIREMENTS

ARTICLE H.1. OPTION PROVISION

Unless the Government exercises its option pursuant to the Option Clause set forth in SECTION I., the purchase order will consist only of the Base Period of the Statement of Work as defined in Sections C and F of the purchase order. Pursuant to FAR Clause 52.217-7, Option for Increased Quantity- Separately Priced Line Item/FAR Clause 52.217-8, Option to Extend Services/FAR Clause 52.217-9, and Option to Extend the Term of the Contract set forth in SECTION I. of this purchase order, the Government may, by unilateral purchase order modification, require the Contractor to perform additional options set forth in the Statement of Work and also defined in Sections C and F of the purchase order. If the Government exercises this option, notice must be given at least 60 days prior to the expiration date of this purchase order, and the price of the purchase order will be increased as set forth in the OPTION PRICES Article in SECTION B of this purchase order.

ARTICLE H.2. SUBCONTRACTING PROVISIONS

The following Small Business Subcontracting provision does not apply to quoters that are a small business under NAICS 541512.

a. Small Business Subcontracting Plan http://www.cpars.gov/

1. The Small Business Subcontracting Plan dated is attached hereto and made a part of this purchase order.

2. The failure of any Contractor or subcontractor to comply in good faith with FAR Clause 52.219-8, entitled "Utilization of Small Business Concerns" incorporated in this purchase order and the attached Subcontracting Plan, will be a material breach of such contract or subcontract and subject to the remedies reserved to the Government under FAR Clause 52.219-16 entitled, "Liquidated Damages-Subcontracting Plan."

b. Subcontracting Reports

The Contractor shall submit the following Subcontracting reports electronically via the "electronic Subcontracting Reporting System (eSRS) at http://www.esrs.gov .

1. Individual Subcontract Reports (ISR)

Regardless of the effective date of this purchase order, the Report shall be due on the following dates for the entire life of this purchase order:

April 30th October 30th Expiration Date of Purchase Order

2. Summary Subcontract Report (SSR)

Regardless of the effective date of this purchase order, the Summary Subcontract Report shall be submitted annually on the following date for the entire life of this purchase order:

October 30th

For both the Individual and Summary Subcontract Reports, the Contracting Officer/Contract Specialist shall be included as a contact for notification purposes at the following e-mail address:

tamara.mcdermott@nih.gov Contracting Officer/Contract Specialist

• The "HHS Subcontracting Plan Template" is included in SECTION J - List of Attachments, of this solicitation.

ARTICLE H.3. INFORMATION SECURITY AND/OR PHYSICAL ACCESS SECURITY

A. Baseline Security Requirements http://www.esrs.gov/ mailto:tamara.mcdermott@nih.gov

• Applicability- The requirements herein apply whether the entire contract or order (hereafter "contract"), or portion thereof, includes either or both of the following:

a. Access (Physical or Logical) to Government Information: A Contractor (and/or any subcontractor) employee will have or will be given the ability to have, routine physical (entry) or logical (electronic) access to government information.

b. Operate a Federal System Containing Information: A Contractor (and/or any subcontractor)will operate a federal system and information technology containing data that supports the HHS mission. In addition to the Federal Acquisition Regulation (FAR) Subpart 2.1 definition of "information technology" (IT), the term as used in this section includes computers, ancillary equipment (including imaging peripherals, input, output, and storage devices necessary for security and surveillance), peripheral equipment designed to be controlled by the central processing unit of a computer, software, firmware and similar procedures, services (including support services), and related resources.

B. Safeguarding Information and Information Systems- In accordance with the Federal Information

Processing Standards Publication (FIPS)199, Standards for Security Categorization of Federal Information and Information Systems, the Contractor (and/or any subcontractor) shall:

a. Protect government information and information systems in order to ensure:

• Confidentiality, which means preserving authorized restrictions on access and disclosure, based on the security terms found in this contract, including means for protecting personal privacy and proprietary information;

• Integrity, which means guarding against improper information modification or destruction, and ensuring information non-repudiation and authenticity; and

• Availability, which means ensuring timely and reliable access to and use of information.

b. Provide security for any Contractor systems, and information contained therein, connected to an HHS network or operated by the Contractor on behalf of HHS regardless of location. In addition, if new or unanticipated threats or hazards are discovered by either the agency or contractor, or if existing safeguards have ceased to function, the discoverer shall immediately, within one (1) hour or less , bring the situation to the attention of the other party.

c. Adopt and implement the policies, procedures, controls, and standards required by the HHS Information Security Program to ensure the confidentiality, integrity, and availability of government information and government information systems for which the Contractor is responsible under this contract or to which the Contractor may otherwise have access under this contract. Obtain the HHS Information Security Program security requirements, outlined in the HHS Information Security and Privacy Policy (IS2P), by contacting the CO/COR or emailing fisma@hhs.gov.

d. Comply with the Privacy Act requirements.

mailto:fisma@hhs.gov mailto:fisma@hhs.gov

C. Information Security Categorization- In accordance with FIPS 199 and National Institute of Standards and Technology (NIST) Special Publication (SP) 800-60, Volume II: Appendices to Guide for Mapping Types of Information and Information Systems to Security Categories, Contractor Non- Disclosure Agreement and based on information provided by the ISSO, CISO, or other security representative, the risk level for each Security Objective and the Overall Risk Level, which is the highest watermark of the three factors…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .