S02-RFQ 36C10A23Q0128 6.26.23.pdf

PDF 1 MB Posted

Attached to
Medallia Software as a Service (SaaS) IDIQ Federal contract opportunity
Solicitation number
36C10A23Q0128_
Issued by
Department of Veterans Affairs Technology Acquisition Center Austin

About this file

This is a solicitation for an indefinite delivery requirements contract vehicle for Medallia Software as a Service (SaaS). The solicitation is seeking subscriptions to Medallia's Enterprise Customer Experience Suite SaaS tools to enable organizations to easily store content, collaborate internally and externally, and capture and analyze customer experience feedback. Required tools include Medallia Experience Cloud, Medallia Ideas, Medallia Experience Orchestration, and other Medallia services. The contractor must provide the tools for a 12-month period and ensure they meet requirements such as FEDRAMP High authorization, 508 compliance, and integration with VA systems. The contractor must also provide assessment, authorization and continuous monitoring support. Offers are due by July 12, 2023. The Department of Veterans Affairs Technology Acquisition Center - Austin will administer the contract.

View the file

Other files for this federal contract opportunity

Other files attached to Medallia Software as a Service (SaaS) IDIQ, newest first.
File Type Posted
P03-JA Medallia SaaS V.12 Redacted.pdf PDF
S02-Attachment 2 - Price Evaluation - Medallia Software as a Service (SaaS) IDIQ.xlsx XLSX spreadsheet

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

PAGE 1 OF 1. REQUISITION NO.

2. CONTRACT NO. 3. AWARD/EFFECTIVE DATE 4. ORDER NO. 5. SOLICITATION NUMBER 6. SOLICITATION ISSUE DATE

a. NAME b. TELEPHONE NO. (No Collect Calls) 8. OFFER DUE DATE/LOCAL

TIME

9. ISSUED BY CODE 10. THIS ACQUISITION IS UNRESTRICTED OR SET ASIDE: % FOR:

SMALL BUSINESS

HUBZONE SMALL

BUSINESS

SERVICE-DISABLED

VETERAN-OWNED

SMALL BUSINESS

WOMEN-OWNED SMALL BUSINESS

(WOSB) ELIGIBLE UNDER THE WOMEN-OWNED

SMALL BUSINESS PROGRAM

EDWOSB

8(A)

NAICS:

SIZE STANDARD:

11. DELIVERY FOR FOB DESTINA-

TION UNLESS BLOCK IS

MARKED

SEE SCHEDULE

12. DISCOUNT TERMS

13a. THIS CONTRACT IS A

RATED ORDER UNDER

DPAS (15 CFR 700)

13b. RATING

14. METHOD OF SOLICITATION

RFQ IFB RFP

15. DELIVER TO CODE 16. ADMINISTERED BY CODE

17a. CONTRACTOR/OFFEROR CODE FACILITY CODE 18a. PAYMENT WILL BE MADE BY CODE

TELEPHONE NO. DUNS: DUNS+4:

PHONE: FAX:

17b. CHECK IF REMITTANCE IS DIFFERENT AND PUT SUCH ADDRESS IN OFFER

18b. SUBMIT INVOICES TO ADDRESS SHOWN IN BLOCK 18a UNLESS BLOCK BELOW IS CHECKED

SEE ADDENDUM

19. 20. 21. 22. 23. 24.

ITEM NO. SCHEDULE OF SUPPLIES/SERVICES QUANTITY UNIT UNIT PRICE AMOUNT

(Use Reverse and/or Attach Additional Sheets as Necessary)

25. ACCOUNTING AND APPROPRIATION DATA 26. TOTAL AWARD AMOUNT (For Govt. Use Only)

27a. SOLICITATION INCORPORATES BY REFERENCE FAR 52.212-1, 52.212-4. FAR 52.212-3 AND 52.212-5 ARE ATTACHED. ADDENDA ARE ARE NOT ATTACHED.

27b. CONTRACT/PURCHASE ORDER INCORPORATES BY REFERENCE FAR 52.212-4. FAR 52.212-5 IS ATTACHED. ADDENDA ARE ARE NOT ATTACHED

28. CONTRACTOR IS REQUIRED TO SIGN THIS DOCUMENT AND RETURN _______________ 29. AWARD OF CONTRACT: REF. ___________________________________ OFFER COPIES TO ISSUING OFFICE. CONTRACTOR AGREES TO FURNISH AND DATED ________________________________. YOUR OFFER ON SOLICITATION DELIVER ALL ITEMS SET FORTH OR OTHERWISE IDENTIFIED ABOVE AND ON ANY (BLOCK 5), INCLUDING ANY ADDITIONS OR CHANGES WHICH ARE ADDITIONAL SHEETS SUBJECT TO THE TERMS AND CONDITIONS SPECIFIED SET FORTH HEREIN IS ACCEPTED AS TO ITEMS:

30a. SIGNATURE OF OFFEROR/CONTRACTOR 31a. UNITED STATES OF AMERICA (SIGNATURE OF CONTRACTING OFFICER)

30b. NAME AND TITLE OF SIGNER (TYPE OR PRINT) 30c. DATE SIGNED 31b. NAME OF CONTRACTING OFFICER (TYPE OR PRINT) 31c. DATE SIGNED

AUTHORIZED FOR LOCAL REPRODUCTION (REV. NOV 2021)

PREVIOUS EDITION IS NOT USABLE Prescribed by GSA - FAR (48 CFR) 53.212

7. FOR SOLICITATION

INFORMATION CALL:

STANDARD FORM 1449

SOLICITATION/CONTRACT/ORDER FOR COMMERCIAL PRODUCTS AND COMMERCIAL SERVICES

OFFEROR TO COMPLETE BLOCKS 12, 17, 23, 24, & 30

TAC-Austin

36C10A23Q0128

Matthew Sanchez matthew.sanchez2@va.gov 5129814465

Department of Veterans Affairs

Technology Acquisition Center - Austin 1701 Directors Blvd, Suite 600 Austin TX 78744

X 100

X Y

541519

150 EMP

N/A

X

See Schedule

Y

Department of Veterans Affairs

Technology Acquisition Center - Austin 1701 Directors Blvd, Suite 600 Austin TX 78744

Y

See website at:

http://www.fsc.va.gov/einvoice.asp

(877) 353-9791

Indefinite Delivery Requirements Contract Vehicle for Medallia Software as a Service (SaaS)

See Schedule B.1 for Schedule of Supplies and Services

See Continuation Page

See CONTINUATION Page

X X

Mary Accomado

06-26-2023

07-12-2023 1300 CST

36C10A23Q0128

SECTION B - CONTINUATION OF SF 1449 BLOCKS

B.1 SCHEDULE OF SUPPLIES AND SERVICES

The contractor shall deliver the requirements detailed in Section D, Attachment 1 – titled "Customer Experience Suite Software as a Service (SaaS) Tool" dated April 14, 2023.

Medallia Software. The Government will place orders based on prices identified in Attachment 2 – Medallia Software as a Service (SaaS) Schedule B Pricing through the process described in Section B, Paragraph B.3, “Ordering Procedures” and payment shall be made in accordance with Section B, Paragraph B.5, “Accounting and Appropriation Data”.

CLIN Description of Supplies/Services

QTY Unit Unit Price Total

Medallia SaaS Solutions See Attachment 1, Product Description Inspection/Acceptance/ FOB: Destination ARM: To be identified on individual orders.

Product Service Code: DA10

See Attachment 2

00XX Medallia SaaS Program Implementation and Management

1 JB NSP NSP

00XX

AA

ATO Details 1 JB NSP NSP

00XX

AB

Monthly Plan of Action and Milestones (POAM) findings reports

12 JB NSP NSP

00xxA C

Bi-Weekly Systems Administration

1 JB NSP NSP

00XX

AD

Management Report 1 JB NS NSP

00XX

AE

Contract Program Management Plan

1 JB NSP NSP

00XX

AF

Technical Refreshment Proposal

1 JB NSP NSP

Total Contract Value (inclusive of all ordering periods) $

Governing Law (continuation of Schedule of Supplies and Services above):

Federal law and regulations, including the Federal Acquisition Regulations (FAR), shall govern this Contract/Order. Commercial license agreements may be made a part of this

Contract/Order but only if both parties expressly make them an addendum hereto, as permitted by FAR 12.212. If the commercial license agreement is not made an addendum, it shall not apply, govern, be a part of or have any effect whatsoever on the Contract/Order; this includes, but is not limited to, any agreement embedded in the computer software (clickwrap), any agreement that is otherwise delivered with or provided to the Government with the commercial computer software or documentation (shrinkwrap), or any other license agreement otherwise referred to in any document. If a commercial license agreement is made an addendum, only those provisions addressing data rights regarding the Government’s use, duplication and disclosure of data (e.g., restricted computer software) are included and made a part of this Contract/Order, and only to the extent that those provisions are not duplicative or inconsistent with Federal law, Federal regulation, the incorporated FAR clauses and the provisions of this Contract/Order; those provisions in the commercial license agreement that do not address data rights regarding the Government’s use, duplication and disclosure of data shall not be included or made a part of the Contract/Order. Federal law and regulation including, without limitation, the Contract Disputes Act (41 U.S.C. § 7101 et seq.), the Anti-Deficiency Act (31 U.S.C. § 1341 et seq.), the Competition in Contracting Act (41 U.S.C. § 3301 et seq.), the Prompt Payment Act (31 U.S.C. §3901 et seq.), Contracts for Data Processing or Maintenance (38 USC § 5725), and FAR clauses 52.212-4, 52.227-14, 52.227-19 shall supersede, control, and render ineffective any inconsistent, conflicting, or duplicative provision in any commercial license agreement. In the event of conflict between this clause and any provision in the Contract/Order or the commercial license agreement or elsewhere, the terms of this clause shall prevail. The Contractor shall deliver to the Government all data first produced under this Contract/Order with unlimited rights as defined by FAR 52.227-14. Claims of patent or copyright infringement brought against the Government as a party shall be defended by the U.S.

Department of Justice (DOJ in accordance with 28 U.S.C. § 516; at the discretion of DOJ, the Contractor may be allowed reasonable participation in the defense of the litigation. Any additional changes to the Contract/Order must be made by contract/order modification (Standard Form 30) and shall only be made by a warranted Contracting Officer. Nothing in this Contract/Order or any commercial license agreement shall be construed as a waiver of sovereign immunity.

SOFTWARE LICENSE, MAINTENANCE AND TECHNICAL SUPPORT:

(1) Definitions.

a) Licensee. The term “licensee” shall mean the U.S. Department of Veterans Affairs (“VA”) and is synonymous with “Government.”

b) Licensor. The term “licensor” shall mean the Contractor having the necessary license or ownership rights to deliver license, software maintenance and support of the computer software being acquired.

The term “Contractor” is the party identified in Block 17a on the SF1449. If the Contractor is a reseller and not the Licensor, the Contractor remains responsible for performance under this Contract/Order.

c) Software. The term “software” shall mean the licensed computer software product(s) cited in the Schedule of Supplies/Services.

d) Maintenance. The term “maintenance” is the process of enhancing and optimizing software, as well as remedying defects. It shall include all new fixes, patches, releases, updates, versions and upgrades, as further defined below.

e) Technical Support. The term “technical support” refers to the range of services providing assistance for the software via the telephone, email, a website or otherwise.

f) Release or Update. The term “release” or “update” are terms that refer to a revision of software that contains defect corrections, minor enhancements or improvements of the software’s functionality. This is usually designated by a change in the number to the right of the decimal point (e.g., from Version 5.3 to 5.4). An example of an update is the addition of new hardware.

g) Version or Upgrade. The term “version” or “upgrade” are terms that refer to a revision of software that contains new or improved functionality. This is usually designated by a change in the number to the left of the decimal point (e.g., from Version 5.4 to 6).

(2) Software License.

a) Unless otherwise stated in the Schedule of Supplies/Services, the Performance Work Statement or Product Description, the software license provided to the Government is a perpetual, nonexclusive license to use the software.

b) The Government may use the software in a networked environment.

c) Any dispute regarding the license grant or usage limitations shall be resolved in accordance with the Disputes Clause incorporated in FAR 52.212-4(d).

d) All limitations of software usage are expressly stated in the Schedule of Supplies/Services and the Performance Work Statement/Product Description.

(3) Software Maintenance and Technical Support.

a) If the Government desires to continue software maintenance and support beyond the period of performance identified in this Contract/Order, the Government will issue a separate contract or order for maintenance and support. Conversely, if a contract or order for continuing software maintenance and technical support is not received, the Contractor is neither authorized nor permitted to renew any of the previously furnished services.

b) The Contractor shall provide software support services, which includes periodic updates, enhancements and corrections to the software, and reasonable technical support, all of which are customarily provided by the Contractor to its commercial customers so as to cause the software to perform according to its specifications, documentation or demonstrated claims.

c) Any telephone support provided by Contractor shall be at no additional cost.

d) The Contractor shall provide all maintenance services in a timely manner in accordance with the Contractor’s customary practice or as defined in the Performance Work Statement or Product Description. However, prolonged delay (exceeding 2 business days) in resolving software problems will be noted in the Government’s various past performance records on the Contractor (e.g., www.cpars.gov).

e) If the Government allows the maintenance and support to lapse and subsequently wishes to reinstate it, any reinstatement fee charged shall not exceed the amounts that would have been charged if the Government had not allowed the subscription to lapse.

(4) Disabling Software Code.

The Government requires delivery of computer software that does not contain any code that will, upon the occurrence or the nonoccurrence of any event, disable the software. Such code includes but is not limited to a computer virus, restrictive key, node lock, time-out or other function, whether implemented by electronic, mechanical, or other means, which limits or hinders the use or access to any computer software based on residency on a specific hardware configuration, frequency of duration of use, or other limiting criteria. If any such disabling code is present, the Contractor agrees to indemnify the Government for all damages suffered as a result of a disabling caused by such code, and the contractor agrees to remove such code upon the Government’s request at no extra cost to the Government. Inability of the Contractor to remove the disabling software code will be considered an inexcusable delay and a material breach of contract, and the Government may exercise its right to terminate for cause. In addition, the Government is permitted to remove the code as it deems appropriate and charge the Contractor for consideration for the time and effort expended in removing the code.

(5) Manuals and Publications.

Upon Government request, the Contractor shall furnish the most current version of the user manual and publications for all products/services provided under this Contract/Order at no cost.

B.2 CONTRACT MINIMUM GUARANTEE

In accordance with Section C, Federal Acquisition Regulation (FAR) Clause 52.216-22 entitled, “Indefinite Quantity” the Minimum guaranteed value under the Medallia http://www.cpars.gov/

Software as a Service (SaaS) contract is $250,000.00 and shall be met through the issuance of the first delivery order.

B.3 ORDERING PROCEDURES

a. Orders against this contract will be issued verbally or through execution of a signed order at the sole discretion of the Government by a VA Contracting Officer during the period of the award date through 60 months thereafter. Individual orders may include options for extended terms and increased quantities. Performance is authorized under any order issued against this Requirements Contract for up to 12 months after the end of the last ordering period. Upon receipt of an order, the contractor shall provide the supplies and services at the prices set forth in the schedule; see Attachment 2.

b. Orders may be issued only as Firm Fixed Price. Each order is a stand-alone order.

B.4 CONTRACT ADMINISTRATION DATA

1. Contract Administration: All contract administration matters will be handled by the following individuals:

a. CONTRACTOR: See Block 17a

b. GOVERNMENT: Contracting Officer 36C10A See Block 31b Department of Veterans Affairs Technology Acquisition Center – Division G 23 Christopher Way Eatontown, New Jersey 07724

2. CONTRACTOR REMITTANCE ADDRESS: All payments by the Government to the contractor will be made in accordance with:

[X] 52.232-33, Payment by Electronic Funds Transfer—System For Award Management, or

[] 52.232-36, Payment by Third Party

3. INVOICES: Invoices shall be submitted in arrears:

a. Quarterly []

b. Semi-Annually []

c. Other [X] Upon Acceptance

4. GOVERNMENT INVOICE ADDRESS: All Invoices from the contractor shall be submitted electronically in accordance with VAAR Clause 852.232-72 Electronic Submission of Payment Requests.

See website at:

http://www.fsc.va.gov/einvoice.asp

ACKNOWLEDGMENT OF AMENDMENTS: The offeror acknowledges receipt of amendments to the Solicitation numbered and dated as follows:

AMENDMENT NO DATE

B.5 ACCOUNTING AND APPROPRIATION DATA

Accounting and Appropriation data and invoicing information will be identified on individual task orders issued against this contract

SECTION C - CONTRACT CLAUSES

ADDENDUM TO FAR 52.212-4 CONTRACT TERMS AND CONDITIONS-

COMMERCIAL PRODUCTS AND SERVICES (DEC 2022)

Clauses that are incorporated by reference (by Citation Number, Title, and Date), have the same force and effect as if they were given in full text. Upon request, the Contracting Officer will make their full text available.

The following clauses are incorporated into 52.212-4 as an addendum to this contract:

C.1 FAR 52.252-2 CLAUSES INCORPORATED BY REFERENCE (FEB 1998)

This contract incorporates one or more clauses by reference, with the same force and effect as if they were given in full text. Upon request, the Contracting Officer will make their full text available. Also, the full text of a clause may be accessed electronically at this/these address(es):

http://www.acquisition.gov/far/index.html http://www.va.gov/oal/library/vaar/

(End of Clause)

FAR

Number

Title Date

52.203-3 GRATUITIES APR 1984

52.203-12 LIMITATION ON PAYMENTS TO INFLUENCE CERTAIN

FEDERAL TRANSACTIONS

JUN 2020

52.204-4 PRINTED OR COPIED DOUBLE-SIDED ON

POSTCONSUMER FIBER CONTENT PAPER

MAY 2011

52.204-13 SYSTEM FOR AWARD MANAGEMENT MAINTENANCE OCT 2018

52.204-18 COMMERCIAL AND GOVERNMENT ENTITY CODE

MAINTENANCE

AUG 2020

52.204-21 BASIC SAFEGUARDING OF COVERED CONTRACTOR

INFORMATION SYSTEMS

NOV 2021

52.227-1 AUTHORIZATION AND CONSENT JUN 2020

52.227-2 NOTICE AND ASSISTANCE REGARDING PATENT AND

COPYRIGHT INFRINGEMENT

JUN 2020

52.227-14 RIGHTS IN DATA—GENERAL MAY 2014

52.227-16 ADDITIONAL DATA REQUIREMENTS JUN 1987

52.227-19 COMMERCIAL COMPUTER SOFTWARE LICENSE DEC 2007

52.232-40 ACCELERATED PAYMENTS TO SMALL BUSINESS NOV 2021

52.242-13 BANKRUPTCY JUL 1995

C.2 FAR 52.216-18 ORDERING (AUG 2020)

(a) Any supplies and services to be furnished under this contract shall be ordered by issuance of delivery orders or task orders by the individuals or activities designated in the Schedule. Such orders may be issued from July 1, 2023 through June 30, 2028 .

(b) All delivery orders or task orders are subject to the terms and conditions of this contract. In the event of conflict between a delivery order or task order and this contract, the contract shall control.

(c) A delivery order or task order is considered "issued" when—

(1) If sent by mail (includes transmittal by U.S. mail or private delivery service), the Government deposits the order in the mail;

(2) If sent by fax, the Government transmits the order to the Contractor’s fax number; or

(3) If sent electronically, the Government either—

(i) Posts a copy of the delivery order or task order to a Government document access system, and notice is sent to the Contractor; or

(ii) Distributes the delivery order or task order via email to the Contractor’s email address.

(d) Orders may be issued by methods other than those enumerated in this clause only if authorized in the contract.

(End of Clause)

C.3 FAR 52.216-19 ORDER LIMITATIONS (OCT 1995)

(a) Minimum order. When the Government requires supplies or services covered by this contract in an amount of less than $250,000.00, the Government is not obligated to purchase, nor is the Contractor obligated to furnish, those supplies or services under the contract.

(b) Maximum order. The Contractor is not obligated to honor—

(1) Any order for a single item in excess of $8,000,000.00.

(2) Any order for a combination of items in excess of $15,000,000.00; or

(3) A series of orders from the same ordering office within 5 days that together call for quantities exceeding the limitation in paragraph (b)(1) or (2) of this section.

(c) If this is a requirements contract (i.e., includes the Requirements clause at subsection 52.216-21 of the Federal Acquisition Regulation (FAR)), the Government is not required to order a part of any one requirement from the Contractor if that requirement exceeds the maximum-order limitations in paragraph (b) of this section.

(d) Notwithstanding paragraphs (b) and (c) of this section, the Contractor shall honor any order exceeding the maximum order limitations in paragraph (b), unless that order (or orders) is returned to the ordering office within 5 days after issuance, with written notice stating the Contractor's intent not to ship the item (or items) called for and the reasons. Upon receiving this notice, the Government may acquire the supplies or services from another source.

C.4 FAR 52.216-21 REQUIREMENTS CONTRACT (OCT 1995)

(a) This is a requirements contract for the supplies or services specified, and effective for the period stated, in the Schedule. The quantities of supplies or services specified in the Schedule are estimates only and are not purchased by this contract. Except as this contract may otherwise provide, if the Government’s requirements do not result in orders in the quantities described as "estimated" or "maximum" in the Schedule, that fact shall not constitute the basis for an equitable price adjustment.

(b) Delivery or performance shall be made only as authorized by orders issued in accordance with the Ordering clause. Subject to any limitations in the Order Limitations clause or elsewhere in this contract, the Contractor shall furnish to the Government all supplies or services specified in the Schedule and called for by orders issued in accordance with the Ordering clause. The Government may issue orders requiring delivery to multiple destinations or performance at multiple locations.

(c) Except as this contract otherwise provides, the Government shall order from the Contractor all the supplies or services specified in the Schedule that are required to be purchased by the Government activity or activities specified in the Schedule.

(d) The Government is not required to purchase from the Contractor requirements in excess of any limit on total orders under this contract.

(e) If the Government urgently requires delivery of any quantity of an item before the earliest date that delivery may be specified under this contract, and if the Contractor will not accept an order providing for the accelerated delivery, the Government may acquire the urgently required goods or services from another source.

(f) Any order issued during the effective period of this contract and not completed within that period shall be completed by the Contractor within the time specified in the order. The contract shall govern the Contractor’s and Government’s rights and obligations with respect to that order to the same extent as if the order were completed during the contract’s effective period; provided, that the Contractor shall not be required to make any deliveries under this contract after June 30, 2028.

C.5 VAAR 852.201-70 CONTRACTING OFFICER'S REPRESENTATIVE (DEC

2022) The Contracting Officer reserves the right to designate representatives to act for him/her in furnishing technical guidance and advice or generally monitor the work to be performed under this contract. Such designation will be in writing and will define the scope and limitation of the designee’s authority. A copy of the designation letter shall be furnished to the Contractor.

(End of Clause)

C.6 VAAR 852.203-70 COMMERCIAL ADVERTISING (MAY 2018)

The Contractor shall not make reference in its commercial advertising to Department of Veterans Affairs contracts in a manner that states or implies the Department of Veterans Affairs approves or endorses the Contractor’s products or services or considers the Contractor’s products or services superior to other products or services.

C.7 VAAR 852.219-73 VA NOTICE OF TOTAL SET-ASIDE FOR VERIFIED

SERVICE-DISABLED VETERAN-OWNED SMALL BUSINESSES (NOV 2022)

(a) Definitions. As used in this clause—

Covered contractor information system means an information system that is owned or operated by a contractor that processes, stores, or transmits Federal contract information.

Federal contract information means information, not intended for public release, that is provided by or generated for the Government under a contract to develop or deliver a product or service to the Government, but not including information provided by the Government to the public (such as on public Web sites) or simple transactional information, such as necessary to process payments.

Information means any communication or representation of knowledge such as facts, data, or opinions, in any medium or form, including textual, numerical, graphic, cartographic, narrative, or audiovisual (Committee on National Security Systems Instruction (CNSSI) 4009).

Information system means a discrete set of information resources organized for the collection, processing, maintenance, use, sharing, dissemination, or disposition of information (44 U.S.C. 3502).

Safeguarding means measures or controls that are prescribed to protect information systems.

(b) Safeguarding requirements and procedures. (1) The Contractor shall apply the following basic safeguarding requirements and procedures to protect covered contractor information systems. Requirements and procedures for basic safeguarding of covered contractor information systems shall include, at a minimum, the following security controls:

(i) Limit information system access to authorized users, processes acting on behalf of authorized users, or devices (including other information systems).

(ii) Limit information system access to the types of transactions and functions that authorized users are permitted to execute.

(iii) Verify and control/limit connections to and use of external information systems.

(iv) Control information posted or processed on publicly accessible information systems.

(v) Identify information system users, processes acting on behalf of users, or devices.

(vi) Authenticate (or verify) the identities of those users, processes, or devices, as a prerequisite to allowing access to organizational information systems.

(vii) Sanitize or destroy information system media containing Federal Contract Information before disposal or release for reuse.

(viii) Limit physical access to organizational information systems, equipment, and the respective operating environments to authorized individuals.

(ix) Escort visitors and monitor visitor activity; maintain audit logs of physical access; and control and manage physical access devices.

(x) Monitor, control, and protect organizational communications (i.e., information transmitted or received by organizational information systems) at the external boundaries and key internal boundaries of the information systems.

(xi) Implement subnetworks for publicly accessible system components that are physically or logically separated from internal networks.

(xii) Identify, report, and correct information and information system flaws in a timely manner.

(xiii) Provide protection from malicious code at appropriate locations within organizational information systems.

(xiv) Update malicious code protection mechanisms when new releases are available.

(xv) Perform periodic scans of the information system and real-time scans of files from external sources as files are downloaded, opened, or executed.

(2) Other requirements. This clause does not relieve the Contractor of any other specific safeguarding requirements specified by Federal agencies and departments relating to covered contractor information systems generally or other Federal safeguarding requirements for controlled unclassified information (CUI) as established by Executive Order 13556.

(c) Subcontracts. The Contractor shall include the substance of this clause, including this paragraph (c), in subcontracts under this contract (including subcontracts for the acquisition of commercial products or commercial services, other than commercially available off-the-shelf items), in which the subcontractor may have Federal contract information residing in or transiting through its information system.

C.8 VAAR 852.219-75 VA NOTICE OF LIMITATIONS ON

SUBCONTRACTING--CERTIFICATE OF COMPLIANCE FOR SERVICES AND

CONSTRUCTION (JAN 2023) (DEVIATION)

(a) Pursuant to 38 U.S.C. 8127(l)(2), the offeror certifies that—

(1) If awarded a contract (see FAR 2.101 definition), it will comply with the limitations on subcontracting requirement as provided in the solicitation and the resultant contract, as follows:

[Contracting Officer check the appropriate box below based on the predominant NAICS code assigned to the instant acquisition as set forth in FAR 19.102.]

(i) [X ] Services. In the case of a contract for services (except construction), the contractor will not pay more than 50% of the amount paid by the government to it to firms that are not certified SDVOSBs listed in the SBA certification database as set forth in 852.219- 73 or certified VOSBs listed in the SBA certification database as set forth in 852.219-74. Any https://www.acquisition.gov/far/2.101 https://www.acquisition.gov/far/19.102 https://www.va.gov/oal/library/vaar/vaar852.asp#85221973 https://www.va.gov/oal/library/vaar/vaar852.asp#85221973 https://www.va.gov/oal/library/vaar/vaar852.asp#85221974 work that a similarly situated certified SDVOSB/VOSB subcontractor further subcontracts will count towards the 50% subcontract amount that cannot be exceeded. Other direct costs may be excluded to the extent they are not the principal purpose of the acquisition and small business concerns do not provide the service as set forth in 13 CFR 125.6.

(ii) [ ] General construction. In the case of a contract for general construction, the contractor will not pay more than 85% of the amount paid by the government to it to firms that are not certified SDVOSBs listed in the SBA certification database as set forth in 852.219- 73 or certified VOSBs listed in the SBA certification database as set forth in 852.219-74. Any work that a similarly situated certified SDBOSB/VOSB subcontractor further subcontracts will count towards the 85% subcontract amount that cannot be exceeded. Cost of materials are excluded and not considered to be subcontracted.

(iii) [ ] Special trade construction contractors. In the case of a contract for special trade contractors, the contractor will not pay more than 75% of the amount paid by the government to it to firms that are not certified SDVOSBs listed in the SBA certification database as set forth in 852.219-73 or certified VOSBs listed in the SBA certification database as set forth in 852.219-

74. Any work that a similarly situated certified SDBOSB/VOSB subcontractor further subcontracts will count towards the 75% subcontract amount that cannot be exceeded. Cost of materials are excluded and not considered to be subcontracted.

(2) The offeror acknowledges that this certification concerns a matter within the jurisdiction of an Agency of the United States. The offeror further acknowledges that this certification is subject to Title 18, United States Code, Section 1001, and, as such, a false, fictitious, or fraudulent certification may render the offeror subject to criminal, civil, or administrative penalties, including prosecution.

(3) If VA determines that an SDVOSB/VOSB awarded a contract pursuant to 38 U.S.C.

8127 did not act in good faith, such SDVOSB/VOSB shall be subject to any or all of the following:

(i) Referral to the VA Suspension and Debarment Committee;

(ii) A fine under section 16(g)(1) of the Small Business Act (15 U.S.C. 645(g)(1)); and

(iii) Prosecution for violating 18 U.S.C. 1001.

(b) The offeror represents and understands that by submission of its offer and award of a contract it may be required to provide copies of documents or records to VA that VA may review to determine whether the offeror complied with the limitations on subcontracting requirement specified in the contract. Contracting officers may, at their discretion, require the contractor to demonstrate its compliance with the limitations on subcontracting at any time during performance and upon completion of a contract if the information regarding such compliance is not already available to the contracting officer. Evidence of compliance includes, but is not limited to, invoices, copies of subcontracts, or a list of the value of tasks performed.

(c) The offeror further agrees to cooperate fully and make available any documents or records as may be required to enable VA to determine compliance with the limitations on https://www.va.gov/oal/library/vaar/vaar852.asp#85221973 https://www.va.gov/oal/library/vaar/vaar852.asp#85221973 https://www.va.gov/oal/library/vaar/vaar852.asp#85221974 https://www.va.gov/oal/library/vaar/vaar852.asp#85221973 subcontracting requirement. The offeror understands that failure to provide documents as requested by VA may result in remedial action as the Government deems appropriate.

(d) Offeror completed certification/fill-in required. The formal certification must be completed, signed and returned with the offeror’s bid, quotation, or proposal. The Government will not consider offers for award from offerors that do not provide the certification, and all such responses will be deemed ineligible for evaluation and award.

Certification:

I hereby certify that if awarded the contract, [insert name of offeror] will comply with the limitations on subcontracting specified in this clause and in the resultant contract. I further certify that I am authorized to execute this certification on behalf of [insert name of offeror].

Printed Name of Signee: ________________________________________

Printed Title of Signee: _________________________________________

Signature: ___________________________________________________

Date: _____________________

Company Name and Address: ______________________________________

(End of clause)

C.9 VAAR 852.232-72 ELECTRONIC SUBMISSION OF PAYMENT

REQUESTS (NOV 2018)

(a) Definitions. As used in this clause—

(1) Contract financing payment has the meaning given in FAR 32.001;

(2) Designated agency office means the office designated by the purchase order, agreement, or contract to first receive and review invoices. This office can be contractually designated as the receiving entity. This office may be different from the office issuing the payment;

(3) Electronic form means an automated system transmitting information electronically according to the accepted electronic data transmission methods and formats identified in paragraph (c) of this clause. Facsimile, email, and scanned documents are not acceptable electronic forms for submission of payment requests;

(4) Invoice payment has the meaning given in FAR 32.001; and

(5) Payment request means any request for contract financing payment or invoice payment submitted by the contractor under this contract.

(b) Electronic payment requests. Except as provided in paragraph (e) of this clause, the contractor shall submit payment requests in electronic form. Purchases paid with a Government-wide commercial purchase card are considered to be an electronic transaction for purposes of this rule, and therefore no additional electronic invoice submission is required.

(c) Data transmission. A contractor must ensure that the data transmission method and format are through one of the following:

(1) VA’s Electronic Invoice Presentment and Payment System at the current website address provided in the contract.

(2) Any system that conforms to the X12 electronic data interchange (EDI) formats established by the Accredited Standards Center (ASC) and chartered by the American National Standards Institute (ANSI).

(d) Invoice requirements. Invoices shall comply with FAR 32.905.

(e) Exceptions. If, based on one of the circumstances in this paragraph (e), the Contracting Officer directs that payment requests be made by mail, the Contractor shall submit payment requests by mail through the United States Postal Service to the designated agency office.

Submission of payment requests by mail may be required for—

(1) Awards made to foreign vendors for work performed outside the United States;

(2) Classified contracts or purchases when electronic submission and processing of payment requests could compromise the safeguarding of classified or privacy information;

(3) Contracts awarded by contracting officers in the conduct of emergency operations, such as responses to national emergencies;

(4) Solicitations or contracts in which the designated agency office is a VA entity other than the VA Financial Services Center in Austin, Texas; or

(5) Solicitations or contracts in which the VA designated agency office does not have electronic invoicing capability as described above.

(End of Clause)

C.10 VAAR 852.239-70 SECURITY REQUIREMENTS FOR INFORMATION

TECHNOLOGY RESOURCES (FEB 2023)

(a) Definitions. As used in this clause—

Information technology has the same meaning in FAR 2.101 and also means Information and Communication Technology (ICT).

Information system security plan means a formal document that provides an overview of the security requirements for an information system and describes the security controls in place or planned for meeting those requirements.

(b) Responsibilities. The Contractor shall be responsible for information system security for all systems connected to a Department of Veterans Affairs (VA) network or operated by the Contractor for VA, regardless of location. This clause is applicable to all or any part of the contract that includes information technology resources or services in which the Contractor has physical or other system access to VA information that directly supports the mission of VA.

Examples of tasks that require security provisions include—

(1) Hosting of VA e-Government sites or other information technology operations;

https://www.acquisition.gov/far/part-2#FAR_2_101

(2) Acquisition, transmission, or analysis of data owned by VA with significant replacement cost should the contractor's copy be corrupted; and

(3) Access to VA general support systems/major applications at a level beyond that granted the general public, e.g., bypassing a firewall.

(c) Information system security plan. The Contractor shall develop, provide, implement, and maintain an Information System Security Plan. VA information systems must have an information system security plan that provides an overview of the security requirements for the system and describes the security controls in place or the plan for meeting those requirements.

This plan shall describe the processes and procedures that the Contractor will follow to ensure appropriate security of information system resources developed, processed, or used under this contract. The information system security plan should include implementation status, responsible entities, resources, and estimated completion dates. Information system security plans may also include, but are not limited to, a compiled list of system characteristics, and key security-related documents such as a risk assessment, PIA, system interconnection agreements, contingency plan, security configurations, configuration management plan, and incident response plan. The plan shall address the specific contract requirements regarding information systems related support or services included in the contract, to include the performance work statement (PWS) or statement of work (SOW). The Contractor's Information System Security Plan shall comply with applicable Federal Laws that include, but are not limited to, 40 U.S.C. 11331, the Federal Information Security Modernization Act (FISMA) of 2014 and the E-Government Act of 2002. The plan shall meet information system security requirements in accordance with Federal and VA policies and procedures, and as amended during the term of this contract, and include, but are not limited to the following.

(1) OMB Circular A-130, Managing Information as a Strategic Resource;

(2) National Institute of Standards and Technology (NIST) Guidelines; and

(3) VA Directive 6500, VA Cybersecurity Program, and the directives and handbooks in the VA 6500 series related to VA information (including VA sensitive information and sensitive personal information and information systems security and privacy), as well as those set forth in the contract specifications, statement of work, or performance work statement. These include, but are not limited to, VA Handbook 6500.6, Contract Security; and VA Directive and Handbook 0710, Personnel Security and Suitability Program, which establishes VA’s procedures, responsibilities, and processes for complying with current Federal law, Executive Orders, policies, regulations, standards and guidance for protecting VA information, information systems (see 802.101, Definitions) security and privacy, and adhering to personnel security requirements when accessing VA information or information systems.

(d) Submittal of plan. Within 90 days after contract award, the Contractor shall submit the Information System Security Plan to the Contracting Officer for review and approval.

(e) Security accreditation. As required by current VA policy, the Contractor shall submit written proof of information system security accreditation to the Contracting Officer for non-VA owned systems. Such written proof may be furnished either by the Contractor or by a third party.

Accreditation shall be in accordance with VA policy available from the Contracting Officer upon request. The Contractor shall submit for acceptance by the Contracting Officer along with this accreditation a final information system security plan, such as a risk assessment, security test and evaluation, and disaster recovery plan/continuity of operations plan. The accreditation and the final information system security plan and the accompanying documents, such as a risk assessment, security test and evaluation, and disaster recovery/continuity of operations plan.

https://www.govinfo.gov/content/pkg/USCODE-2021-title40/pdf/USCODE-2021-title40-subtitleIII-chap113-subchapIII-sec11331.pdf https://www.va.gov/vapubs/viewPublication.asp?Pub_ID=1254&FType=2 https://www.va.gov/vapubs/viewPublication.asp?Pub_ID=471&FType=2 https://www.va.gov/vapubs/viewPublication.asp?Pub_ID=487&FType=2 https://www.va.gov/vapubs/viewPublication.asp?Pub_ID=832&FType=2 https://www.va.gov/oal/library/vaar/vaar802.asp#802101

(f) Annual validation. On an annual basis, the Contractor shall verify in writing to the Contracting Officer that the Information System Security Plan remains valid.

(g) Banners. The Contractor shall ensure that the official VA banners are displayed on all VA systems (both public and private) operated by the Contractor that contain Privacy Act information before allowing anyone access to the system. The Office of Information Technology will make official VA banners available to the Contractor.

(h) Screening and access. The Contractor shall screen all personnel requiring privileged access or limited privileged access to systems operated by the Contractor for VA or interconnected to a VA network in accordance with VA Directives and Handbooks referenced in paragraph (c) of this clause.

(i) Training. The Contractor shall ensure that its employees performing services under this contract complete VA security awareness training on an annual basis. This includes signing an acknowledgment that they have read, understand, and agree to abide by the VA Information Security Rules of Behavior (VA National Rules of Behavior) as required by 38 U.S.C. 5723; FAR 39.105, Privacy; clause 852.204-71, Information and Information Systems Security, and this clause on an annual basis.

(j) Government access. The Contractor shall provide the Government access to the Contractor's and subcontractors' facilities, installations, operations, documentation, databases, and personnel used in performance of the contract. The Contractor shall provide access to enable a program of information system inspection (to include vulnerability testing), investigation and audit (to safeguard against threats and hazards to the integrity, availability and confidentiality of VA data or to the function of information systems operated on behalf of VA), and to preserve evidence of computer crime.

(k) Notification of termination of employees. The Contractor shall immediately notify the Contracting Officer when an employee who has access to VA information systems or data terminates employment.

(l) Subcontractor flow down requirement. The Contractor shall incorporate and flow down the substance of this clause to all subcontracts that meet the conditions in paragraph (a) of this clause.

(End of clause)

C11 VAAR 852.239-73 INFORMATION SYSTEM HOSTING, OPERATION,

MAINTENANCE, OR USE (FEB 2023)

(a) Definitions. As used in this clause -

Assessment and Authorization (A&A) means the process used to ensure information systems including Major Applications and General Support Systems have effective security safeguards which have been implemented, planned for, and documented in an Information Technology Security Plan. The A&A process per applicable VA policies and procedures is the mechanism by which VA provides an Authorization to Operate (ATO), the official management decision given by the VA to authorize operation of an information system (see VA Handbook 6500 for additional details).

https://www.govinfo.gov/content/pkg/USCODE-2021-title38/pdf/USCODE-2021-title38-partIV-chap57-subchapIII-sec5723.pdf https://www.acquisition.gov/far/part-39#FAR_39_105 https://www.acquisition.gov/far/part-39#FAR_39_105 https://www.va.gov/oal/library/vaar/vaar852.asp#85220471

Information system security plan means a formal document that provides an overview of the security requirements for an information system and describes the security controls in place or planned for meeting those requirements.

(b) Hosting, operation, maintenance, or use at non-VA facilities. For information systems that are hosted, operated, maintained, or used on behalf of VA at non-VA facilities, Contractors/subcontractors are fully responsible and accountable for ensuring compliance with the applicable Health Insurance Portability and Accountability (HIPAA) Act of 1996 (HIPAA) Privacy and Security Rules, the Privacy Act and other required VA confidentiality statutes included in VA's mandatory yearly training and privacy handbooks, Federal Information Security Modernization Act (FISMA), National Institute of Standards and Technology (NIST), Federal Information Processing Standards (FIPS), and VA security and privacy directives and handbooks. This includes conducting compliant risk assessments, routine vulnerability scanning, system patching and change management procedures, and the completion of an acceptable contingency plan for each system. The Contractor's security control procedures must be equivalent to or exceed, those procedures used to secure VA systems. A Privacy Impact Assessment (PIA) must also be provided to the COR and approved by VA Privacy Service prior to approval to operate. All external internet connections to VA's network involving VA information must be in accordance with the Trusted internet Connections (TIC) Reference Architecture and reviewed and approved by VA prior to implementation. For Cloud Services hosting, the Contractor shall also ensure compliance with the Federal Risk and Authorization Management Program (FedRAMP).

(c) Collecting, processing, transmitting, and storing of VA sensitive information. Adequate security controls for collecting, processing, transmitting, and storing of VA sensitive information, must be in place, tested, and approved by VA prior to hosting, operation, maintenance, or use of the information system, or systems by or on behalf of VA. These security controls are to be assessed and stated within the Information System Security Plan and if these controls are determined not to be in place, or inadequate, a Plan of Action and Milestones (POA&M) must be submitted and approved prior to the collection, processing, transmitting, and storing of VA sensitive information.

(d) Annual FISMA security controls assessment. The Contractor/subcontractor's system must adhere to all FISMA, FIPS, and NIST standards related to the annual FISMA security controls assessment and review and update the Privacy Impact Assessment. Any deficiencies noted during this assessment must be provided to the Contracting Officer for entry into VA's POA&M management process. The Contractor/subcontractor must use VA's POA&M process to document planned remedial actions to address any deficiencies in information security policies, procedures, and practices, and the completion of those activities. Security deficiencies must be corrected within the timeframes specified by the VA in the performance work statement (PWS) or statement of work (SOW), or in the approved remediation plan through the VA POA&M process. Contractor/subcontractor procedures are subject to periodic, unannounced assessments by VA officials, including the VA Office of Inspector General. The physical security aspects associated with Contractor/subcontractor activities must also be subject to such assessments. The results of an annual review or a major change in the cybersecurity posture at any time may indicate the need for reassessment and reauthorization of the system. If major changes to the system occur that may affect the privacy or security of the data or the system, the A&A of the system may need to be reviewed, retested and re-authorized per VA Handbook 6500. This may require reviewing and updating all of the documentation as described in VA Handbook 6500.6 (e.g., System Security Plan, Contingency Plan). See VA Handbook 6500.6 for a list of documentation. The VA Information System Risk Management (ISRM) office can provide guidance on whether a new A&A would be necessary.

(e) Annual self-assessment. The Contractor/subcontractor must conduct an annual self-assessment on all systems and outsourced services as required. Both hard copy and electronic copies of the assessment must be provided to the COR. VA reserves the right to conduct such an assessment using government personnel or another Contractor/subcontractor. The Contractor/subcontractor must take appropriate and timely action, as may be specifically addressed in the contract, to correct or mitigate any weaknesses discovered during such testing, at no additional cost to the Government to correct Contractor/subcontractor systems and outsourced services.

(f) Prohibition of installation and use of personally-owned or Contractor-owned equipment or software on VA networks. VA prohibits the installation and use of personally-owned or Contractor/subcontractor-owned equipment or software on VA networks. If non-VA owned equipment must be used to fulfill the requirements of a contract, it must be stated in the service agreement, PWS, SOW or contract. All of the security controls required for government furnished equipment (GFE) must also be utilized in approved other equipment (OE) at the Contractor's expense. All remote systems must be equipped with, and use, a VA-approved antivirus (AV) software and a personal (host-based or enclave based) firewall that is configured with a VA-approved configuration. Software must be kept current, including all critical updates and patches.

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .