S02 - RFQ 36C10B25Q0152 Final.pdf

PDF 751 KB Posted

Attached to
Enformion Web Seat License Federal contract opportunity
Solicitation number
36C10B25Q0152
Issued by
Department of Veterans Affairs Technology Acquisition Center Austin

About this file

This document is a Request for Quotation (RFQ) issued by the Department of Veterans Affairs Technology Acquisition Center for an Enformion Web Seat License. The procurement is a small business sole-source acquisition under NAICS code 513210 with a $47M size standard, seeking 90 web seat licenses for the Philadelphia VA Insurance Center to access a public records database. The base contract will be firm-fixed-price with a 12-month base period and four 12-month option periods, allowing VA employees to search public records for veterans and beneficiaries insurance information.

The solicitation (RFQ 36C10B25Q0152) was issued on 03-06-2025, with quotes due by 03-13-2025 at 12:00 PM EST. The database must provide features for accessing accurate, automatically updated public records, with capabilities to classify and share research and search across databases using descriptive terms. The contract will be administered by the VA Technology Acquisition Center in Eatontown, NJ, with payment processed through the VA Financial Services Center in Austin, TX. The total contract value will cover the base year and potential four option years, with 90 web seat licenses to be purchased each period.

View the file

Other files for this federal contract opportunity

Other files attached to Enformion Web Seat License, newest first.
File Type Posted
P09 - Final PD Enformion.pdf PDF
P03 - JA Enformion Final Redacted.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

PAGE 1 OF 1. REQUISITION NO.

2. CONTRACT NO. 3. AWARD/EFFECTIVE DATE 4. ORDER NO. 5. SOLICITATION NUMBER 6. SOLICITATION ISSUE DATE

a. NAME b. TELEPHONE NO. (No Collect Calls) 8. OFFER DUE DATE/LOCAL

TIME

9. ISSUED BY CODE 10. THIS ACQUISITION IS UNRESTRICTED OR SET ASIDE: % FOR:

SMALL BUSINESS

HUBZONE SMALL

BUSINESS

SERVICE-DISABLED

VETERAN-OWNED

SMALL BUSINESS

WOMEN-OWNED SMALL BUSINESS

(WOSB) ELIGIBLE UNDER THE WOMEN-OWNED

SMALL BUSINESS PROGRAM

EDWOSB

8(A)

NAICS:

SIZE STANDARD:

11. DELIVERY FOR FOB DESTINA-

TION UNLESS BLOCK IS

MARKED

SEE SCHEDULE

12. DISCOUNT TERMS

13a. THIS CONTRACT IS A

RATED ORDER UNDER

DPAS (15 CFR 700)

13b. RATING

14. METHOD OF SOLICITATION

RFQ IFB RFP

15. DELIVER TO CODE 16. ADMINISTERED BY CODE

17a. CONTRACTOR/OFFEROR CODE FACILITY CODE 18a. PAYMENT WILL BE MADE BY CODE

TELEPHONE NO. UEI: EFT:

PHONE: FAX:

17b. CHECK IF REMITTANCE IS DIFFERENT AND PUT SUCH ADDRESS IN OFFER

18b. SUBMIT INVOICES TO ADDRESS SHOWN IN BLOCK 18a UNLESS BLOCK BELOW IS CHECKED

SEE ADDENDUM

19. 20. 21. 22. 23. 24.

ITEM NO. SCHEDULE OF SUPPLIES/SERVICES QUANTITY UNIT UNIT PRICE AMOUNT

(Use Reverse and/or Attach Additional Sheets as Necessary)

25. ACCOUNTING AND APPROPRIATION DATA 26. TOTAL AWARD AMOUNT (For Govt. Use Only)

27a. SOLICITATION INCORPORATES BY REFERENCE FAR 52.212-1, 52.212-4. FAR 52.212-3 AND 52.212-5 ARE ATTACHED. ADDENDA ARE ARE NOT ATTACHED.

27b. CONTRACT/PURCHASE ORDER INCORPORATES BY REFERENCE FAR 52.212-4. FAR 52.212-5 IS ATTACHED. ADDENDA ARE ARE NOT ATTACHED

28. CONTRACTOR IS REQUIRED TO SIGN THIS DOCUMENT AND RETURN _______________ 29. AWARD OF CONTRACT: REF. ___________________________________ OFFER COPIES TO ISSUING OFFICE. CONTRACTOR AGREES TO FURNISH AND DATED ________________________________. YOUR OFFER ON SOLICITATION DELIVER ALL ITEMS SET FORTH OR OTHERWISE IDENTIFIED ABOVE AND ON ANY (BLOCK 5), INCLUDING ANY ADDITIONS OR CHANGES WHICH ARE ADDITIONAL SHEETS SUBJECT TO THE TERMS AND CONDITIONS SPECIFIED SET FORTH HEREIN IS ACCEPTED AS TO ITEMS:

30a. SIGNATURE OF OFFEROR/CONTRACTOR 31a. UNITED STATES OF AMERICA (SIGNATURE OF CONTRACTING OFFICER)

30b. NAME AND TITLE OF SIGNER (TYPE OR PRINT) 30c. DATE SIGNED 31b. NAME OF CONTRACTING OFFICER (TYPE OR PRINT) 31c. DATE SIGNED

AUTHORIZED FOR LOCAL REPRODUCTION (REV. NOV 2021)

PREVIOUS EDITION IS NOT USABLE Prescribed by GSA - FAR (48 CFR) 53.212

7. FOR SOLICITATION

INFORMATION CALL:

STANDARD FORM 1449

SOLICITATION/CONTRACT/ORDER FOR COMMERCIAL PRODUCTS AND COMMERCIAL SERVICES

OFFEROR TO COMPLETE BLOCKS 12, 17, 23, 24, & 30

36C10B25Q0152 03-06-2025

Kimberly White (215) 842-2000 4279 03-13-2025

12:00PM EST

Department of Veterans Affairs Technology Acquisition Center

23 Christopher Way Eatontown NJ 07724

X 0

513210

$47M

N/A

X

See Delivery Schedule

Financial Services Center PO Box 149971 Austin TX 78714-8971

See CONTINUATION Page

Enformion Web Seat License See section B.2 Price Schedule and B.7 Product Description

See CONTINUATION Page x X

Stefanie Applegate

36C10B25Q0152

Table of Contents

SECTION B - CONTINUATION OF SF 1449 BLOCKS…………………………………….………4

B.1 REQUIREMENTS BACKGROUND

B.2 SCHEDULE OF SUPPLIES AND SERVICES

B.3 GOVERNING LAW CLAUSE

B.4 SOFTWARE LICENSE, SOFTWARE MAINTENANCE AND SOFTWARE

TECHNICAL SUPPORT:

B.5 CONTRACT ADMINISTRATION DATA

B.6 ACCOUNTING AND APPROPRIATION DATA

B.7 PRODUCT DESCRIPTION

SECTION C - CONTRACT CLAUSES

FAR 52.212-4 CONTRACT TERMS AND CONDITIONS—COMMERCIAL PRODUCTS

AND COMMERCIAL SERVICES (NOV 2021)

C.1 FAR 52.252-2 CLAUSES INCORPORATED BY REFERENCE (FEB 1998)

C.2 FAR 52.204-21 BASIC SAFEGUARDING OF COVERED CONTRACT

INFORMATION SYSTEMS (NOV 2021)

C.3 FAR 52.217-9 OPTION TO EXTEND THE TERM OF THE CONTRACT (MAR 2000)

C.4 FAR 52.212-5 CONTRACT TERMS AND CONDITIONS REQUIRED TO

IMPLEMENT STATUTES OR EXECUTIVE ORDERS – COMMERCIAL ITEMS (JAN

2025)

C.5 FAR 52.227-19 COMMERCIAL COMPUTER SOFTWARE LICENSE (DEC 2007) . 44

C.6 VAAR 852.211-76 LIQUIDATION DAMAGES-REIMBURSEMENT FOR DATA

BREACH COST (FEB 2003)

C.7 VAAR 52.219-75 VA NOTICE OF LIMITATIONS ON SUBCONTRACTING-

CERTIFICATE OF COMPLIANCE FOR SERVICES AND CONSTRUCTION (JAN 2023)

C.8 VAAR 852.242-71 ADMINISTRATIVE CONTRACTING OFFICER (OCT 2020)

SECTION D - CONTRACT DOCUMENTS, EXHIBITS, OR ATTACHMENTS

Attachment 1 – Redacted JA

SECTION E - SOLICITATION PROVISIONS

E1. FAR 521.212-1 INSTRUCTIONS TO OFFEROR – COMMERCIAL PRODUCTS AND

SERVICES (SEP 2023)

E.2 FAR 52.252-1 SOLICITATION PROVISIONS INCORPORATED BY REFERENCE

(FEB 1998)

E.3 FAR 52.204-24 PREDECESSOR OF OFFEROR (AUG 2020)

E.4 FAR 52.204-24 REPRESENTATION REGARDING CERTAIN

TELECOMMUNICATIONS AND VIDEO SURVEILLANCE SERVICES OR EQUIPMENT

(NOV 2021)

E.5 FAR 52.204-26 COVERED TELECOMMUNICATIONS EQUIPMENT OR SERVICES

– REPRESENTATION (OCT 2020)

E. 6 FAR 52.209-11 REPRESENTATION BY CORPORATIONS REGARDING

DELINQUENT TAX LIABILITY OR A FELONY CONVICTION UNDER ANY FEDERAL

LAW (FEB 2016)

E.7 FAR 52.212-3 OFFEROR REPRESENTATIONS AND CERTIFICATIONS—

COMMERCIAL PRODUCTS AND COMMERCIAL SERVICES (DEC 2022)

E.8 FAR 52.233-2 SERVICE OF PROTEST (SEPT 2006)

E.9 QUOTES SUBMISSION INSTRUCTIONS

B.1 REQUIREMENTS BACKGROUND

This is a solicitation for commercial items prepared in accordance with the format in Federal Acquisition Regulation (FAR) Subpart 12.6, as supplemented with additional information included in this notice. Request for Quotation (RFQ) 36C10B25Q0152 is issued to fulfill Enformion LLC, for Enformion Web Seat License. This action is a small business sole source, under North American Industrial Classification System (NAICS) Code 513210 – “Software Publishers”. The size standard for NAICS 513210 is $47M.

Specific requirements are listed in the “Product Description” (see section B.7). All quotes shall contain the minimum information required under FAR Clause 52.212-1 Instructions to Offerors-Commercial Products and Commercial Services, to include its associated addendum (see section E). All proposals received in response to this solicitation will be evaluated in accordance with 52.212-2 EVALUATION—

COMMERCIAL PRODUCTS AND COMMERCIAL SERVICES (NOV 2021)

(MODIFIED). Your proposal, in accordance with FAR 52.212-3 Offeror Representations and Certifications, Commercial Items, shall list your Unique Entity ID (UEI) number, Commercial and Government Entity (CAGE) code, company name, and name, phone number and email of the point of contact authorized to negotiate with the Government.

B.2 SCHEDULE OF SUPPLIES AND SERVICES

Any resulting contract will be awarded on a firm-fixed-price basis as defined by Federal Acquisition Regulation Subpart 16.202. Accordingly, the Contractor shall ensure that any and all costs associated with the Contractor’s proposed application(s), software products, software solution, and/or system, shall be included in the Contractor’s proposed firm-fixed price, and shall serve as the Contractor’s firm-fixed price for the life of any resulting contract. No additional costs or fees relative to the Contractor’s proposed application(s), software products, software solution, and/or system including, but not limited to, licensing costs and any associated licensing maintenance required for the development, delivery, integration, operation, and/or maintenance of the Contractor’s proposed solution will be allowed, accepted, and/or paid by the Government. Software shall be delivered within five business day of award.

Line Item Description QTY

Unit of

Issue Unit Price Extended Price

Base Period All products/services shall be in accordance with the Product Description, entitled “Enformion Web Seat License” as set forth in Section B.7. The period of performance shall be 12-months from date of award.

Application Access - Web Seat License

Product Service Code

(PSC): DA10

North American Industry Classification System

(NAICS): 519290

90 EA $ $

Total Base Period $

This 12-month option period may be exercised in accordance with Federal Acquisition Regulations (FAR) 52.217-9, Option to Extend the Term of the Contract (MAR 2000).

Work shall not commence until, and unless, a formal modification is issued by the Contracting Officer. If exercised, this option shall commence at the end of the previous period. Please be advised that in accordance with Federal Acquisition Regulation (FAR) Part 2.101, a “day” means, unless otherwise specified, a CALENDAR Day. Additionally, deliverables with due dates falling on a weekend or holiday shall be submitted the following Government workday after the weekend or holiday.

Line Item Description QTY Unit of

Issue Unit Price Extended Price

Option Period 1 This Option Year may be exercised IAW FAR 52.217-9 Option to Extend the Term of the Contract (MAR 2000). The period of performance shall be 12-months after date of award through 24 months.

Public Records Database (PRD) Application Access - Web Seat License Product Service Code

(PSC): DA10

North American Industry Classification System

(NAICS): 519290

Total Option Period 1 $

Work shall not commence until, and unless, a formal modification is issued by the Contracting Officer. If exercised, this option shall commence at the end of the previous period. Please be advised that in accordance with Federal Acquisition Regulation (FAR) Part 2.101, a “day” means, unless otherwise specified, a CALENDAR Day. Additionally, deliverables with due dates falling on a weekend or holiday shall be submitted the following Government workday after the weekend or holiday.

Line Item Description QTY

Unit of

Issue Unit Price Extended Price

Option Period 2 This Option Year may be exercised IAW FAR 52.217-9 Option to Extend the Term of the Contract (MAR 2000). The period of performance shall be 12-months from date of award through 36 months.

PRD Application Access - Web Seat License Product Service Code

(PSC): DA10

North American Industry Classification System

(NAICS): 519290

Total Option Period 2 $

Regulations (FAR) 52.217-9, Option to Extend the Term of the Contract (MAR 2000).

Work shall not commence until, and unless, a formal modification is issued by the Contracting Officer. If exercised, this option shall commence at the end of the previous period. Please be advised that in accordance with Federal Acquisition Regulation (FAR) Part 2.101, a “day” means, unless otherwise specified, a CALENDAR Day. Additionally, deliverables with due dates falling on a weekend or holiday shall be submitted the following Government workday after the weekend or holiday.

Line Item Description QTY

Unit of

Issue Unit Price Extended Price

Option Period 3 This Option Year may be exercised IAW FAR 52.217-9 Option to Extend the Term of the Contract (MAR 2000). The period of performance shall be 12-months from date of award through 48 months.

PRD Application Access - Web Seat License Product Service Code

(PSC): DA10

North American Industry Classification System

(NAICS): 519290

Total Option Period 3 $

Work shall not commence until, and unless, a formal modification is issued by the Contracting Officer. If exercised, this option shall commence at the end of the previous period. Please be advised that in accordance with Federal Acquisition Regulation (FAR) Part 2.101, a “day” means, unless otherwise specified, a CALENDAR Day. Additionally, deliverables with due dates falling on a weekend or holiday shall be submitted the following Government workday after the weekend or holiday.

Line Item Description QTY

Unit of

Issue Unit Price Extended Price

Option Period 4 This Option Year may be exercised IAW FAR 52.217-9 Option to Extend the Term of the Contract (MAR 2000). The period of performance shall be 12-months from date of award through 60 months.

Line Item Description QTY

Unit of

Issue Unit Price Extended Price

PRD Application Access - Web Seat License Product Service Code (PSC): DA10 North American Industry Classification System

(NAICS): 519290

90 EA $ $

Total Option Period 4 $

Total Base and Option Periods $

B.3 GOVERNING LAW CLAUSE

Federal law and regulations, including the Federal Acquisition Regulations (FAR), shall govern this Contract/Order. Commercial license agreements may be made a part of this Contract/Order but only if both parties expressly make them an addendum hereto, as permitted by FAR 12.212. If the commercial license agreement is not made an addendum, it shall not apply, govern, be a part of or have any effect whatsoever on the Contract/Order; this includes, but is not limited to, any agreement embedded in the computer software (clickwrap), any agreement that is otherwise delivered with or provided to the Government with the commercial computer software or documentation (shrink-wrap), or any other license agreement otherwise referred to in any document. If a commercial license agreement is made an addendum, only those provisions addressing data rights regarding the Government’s use, duplication and disclosure of data (e.g., restricted computer software) are included and made a part of this Contract/Order, and only to the extent that those provisions are not duplicative or inconsistent with Federal law, Federal regulation, the incorporated FAR clauses and the provisions of this Contract/Order; those provisions in the commercial license agreement that do not address data rights regarding the Government’s use, duplication and disclosure of data shall not be included or made a part of the Contract/Order. Federal law and regulation including, without limitation, the Contract Disputes Act (41 U.S.C. § 7101 et seq.), the Anti-Deficiency Act (31 U.S.C. § 1341 et seq.), the Competition in Contracting Act (41 U.S.C. § 3301 et seq.), the Prompt Payment Act (31 U.S.C. § 3901 et seq.), Contracts for Data Processing or Maintenance (38 USC § 5725), and FAR clauses 52.212-4, 52.227-14, 52.227-19 shall supersede, control, and render ineffective any inconsistent, conflicting, or duplicative provision in any commercial license agreement. In the event of conflict between this clause and any provision in the Contract/Order or the commercial license agreement or elsewhere, the terms of this clause shall prevail. The Contractor shall deliver to the Government all data first produced under this Contract/Order with unlimited rights as defined by FAR 52.227-14.

Claims of patent or copyright infringement brought against the Government as a party shall be defended by the U.S. Department of Justice (DOJ) in accordance with 28 U.S.C. § 516; at the discretion of DOJ, the Contractor may be allowed reasonable participation in the defense of the litigation. Any additional changes to the Contract/Order must be made by modification (Standard Form 30) and shall only be made by a warranted Contracting Officer. Nothing in this Contract/Order or any commercial license agreement shall be construed as a waiver of sovereign immunity.

construed as a waiver of sovereign immunity.

B.4 SOFTWARE LICENSE, SOFTWARE MAINTENANCE AND SOFTWARE

TECHNICAL SUPPORT:

(1). Definitions.

a) Licensee. The term “licensee” shall mean the U.S. Department of Veterans Affairs (“VA”) and is synonymous with “Government.”

b) Licensor. The term “licensor” shall mean the Contractor having the necessary license or ownership rights to deliver license, software maintenance and support of the computer software being acquired. The term “Contractor” is the party identified in Block 17a on the SF1449. If the Contractor is a reseller and not the Licensor, the Contractor remains responsible for performance under this Contract/Order.

c) Software. The term “software” shall mean the licensed computer software product(s) cited in the Schedule of Supplies/Services.

d) Maintenance. The term “maintenance” is the process of enhancing and optimizing software, as well as remedying defects. It shall include all new fixes, patches, releases, updates, versions and upgrades, as further defined below.

e) Technical Support. The term “technical support” refers to the range of services providing assistance for the software via the telephone, email, a website or otherwise.

f) Release or Update. The term “release” or “update” are terms that refer to a revision of software that contains defect corrections, minor enhancements, or improvements of the software’s functionality. This is usually designated by a change in the number to the right of the decimal point (e.g., from Version 5.3 to 5.4). An example of an update is the addition of new hardware.

g) Version or Upgrade. The term “version” or “upgrade” are terms that refer to a revision of software that contains new or improved functionality. This is usually designated by a change in the number to the left of the decimal point (e.g., from Version 5.4 to 6).

(2). Software License.

a) Unless otherwise stated in the Schedule of Supplies/Services, the Performance Work Statement or Product Description, the software license provided to the Government is a perpetual, nonexclusive license to use the software.

b) The Government may use the software in a networked environment.

c) Any dispute regarding the license grant or usage limitations shall be resolved in accordance with the Disputes Clause incorporated in FAR 52.212-4(d).

d) All limitations of software usage are expressly stated in the Schedule of

Supplies/Services and the Performance Work Statement/Product Description.

(3). Software Maintenance and/or Technical Support.

a) If the Government desires to continue software maintenance and support beyond the period of performance identified in this Contract/Order, the Government will issue a separate contract or order for maintenance and support. Conversely, if a contract or order for continuing software maintenance and technical support is not received, the Contractor is neither authorized nor permitted to renew any of the previously furnished services.

b) The Contractor shall provide software support services, which includes periodic updates, enhancements and corrections to the software, and reasonable technical support, all of which are customarily provided by the Contractor to its commercial customers to cause the software to perform according to its specifications, documentation or demonstrated claims.

c) Any telephone support provided by Contractor shall be at no additional cost.

d) The Contractor shall provide all maintenance services in a timely manner in accordance with the Contractor’s customary practice or as defined in the Performance Work Statement or Product Description. However, prolonged delay (exceeding two business days) in resolving software problems will be noted in the Government’s various past performance records on the Contractor (e.g., www.cpars.gov).

e) If the Government allows the maintenance and support to lapse and subsequently wishes to reinstate it, any reinstatement fee charged shall not exceed the amounts that would have been charged if the Government had not allowed the subscription to lapse.

(4). Disabling Software Code.

The Government requires delivery of computer software that does not contain any code that will, upon the occurrence or the nonoccurrence of any event, disable the software.

Such code includes but is not limited to a computer virus, restrictive key, node lock, time-out, or other function, whether implemented by electronic, mechanical, or other means, which limits or hinders the use or access to any computer software based on residency on a specific hardware configuration, frequency of duration of use, or other limiting criteria. If any such disabling code is present, the Contractor agrees to indemnify the Government for all damages suffered as a result of a disabling caused by such code, and the contractor agrees to remove such code upon the Government’s request at no extra cost to the Government. Inability of the Contractor to remove the disabling software code will be considered an inexcusable delay and a material breach of contract, and the Government may exercise its right to terminate for cause. In addition, the Government is permitted to remove the code as it deems appropriate and charge the Contractor for consideration for the time and effort expended in removing the code.

(5). Manuals and Publications.

Upon Government request, the Contractor shall furnish the most current version of the user manual and publications for all products/services provided under this Contract/Order at no cost.

http://www.cpars.gov/

B.5 CONTRACT ADMINISTRATION DATA

1. Contract Administration: All contract administration matters will be handled by the following individuals:

a. CONTRACTOR: See Block 17a

b. GOVERNMENT: Contracting Officer - See Block 31b

Department of Veterans Affairs Technology Acquisition Center

Eatontown, NJ 07724

2. CONTRACTOR REMITTANCE ADDRESS: All payments by the Government to the contractor will be made in accordance with:

[X] 52.232-33, Payment by Electronic Funds Transfer—System for Award

Management, or [] 52.232-36, Payment by Third Party

3. INVOICES: Invoices shall be submitted in arrears:

a. Quarterly []

b. Semi-Annually []

c. Other [X] Upon Government receipt of item(s)]

4. GOVERNMENT INVOICE ADDRESS: All Invoices from the contractor shall be submitted electronically in accordance with VAAR Clause 852.232-72 Electronic Submission of Payment Requests.

See website at: http://www.fsc.va.gov/einvoice.asp

B.6 ACCOUNTING AND APPROPRIATION DATA

Funds in the amount of $TBD are obligated on Deliver Order Number TDB to fund CLIN 0001. The contractor shall reference the Delivery Order/Task Order Number on each invoice submitted for payment.

http://www.fsc.va.gov/einvoice.asp

B.7 PRODUCT DESCRIPTION

1.0 PRODUCT REQUIREMENTS

The Philadelphia VA Insurance Center (VAIC) requires brand name Enformion enterprise web license to a public records database for its employees to efficiently and effectively search public records to acquire information for Veterans and Beneficiaries who are or may be entitled to VA Insurance benefit proceeds. The public record database shall be electronically designed to allow VAIC to easily access accurate public records which are updated automatically to ensure accuracy, provide features that allow VAIC to classify and share research effortlessly, and shall utilize a research engine where VAIC can search all company databases by entering simple descriptive terms or names. The government intends to sole-source the contract to our existing vendor as a firm‐fixed‐price contract.

Enformion’s SaaS Web Seat License provides the Standard Product Offering which includes 42 different data resource features. The VAIC has been using this Vendor’s SaaS solution for over 5 years.

Description Part no. Quantity

Standard Product Offering (details listed in quote)

Web Seat 90

Base Period Year Monthly Public Records Database (PRD) Application Access - Web Seat License

Option Year 1 PRD Application Access - Web Seat License

Web Seat 90

Option Year 2 PRD Application Access - Web Seat License

Web Seat 90

Option Year 3 PRD Application Access - Web Seat License

Web Seat 90

Option Year 4 PRD Application Access - Web Seat License

2.0 NOTICE OF THE FEDERAL ACCESSIBILITY LAW AFFECTING ALL

INFORMATION AND COMMUNICATION TECHNOLOGY (ICT) PROCUREMENTS

(SECTION 508)

On January 18, 2017, the Architectural and Transportation Barriers Compliance Board (Access Board) revised and updated, in a single rulemaking, standards for electronic and information technology developed, procured, maintained, or used by Federal agencies covered by Section 508 of the Rehabilitation Act of 1973, as well as our guidelines for telecommunications equipment and customer premises equipment covered by Section 255 of the Communications Act of 1934. The revisions and updates to the Section 508-based standards and Section 255-based guidelines are intended to ensure that information and communication technology (ICT) covered by the respective statutes is accessible to and usable by individuals with disabilities.

2.1 SECTION 508 – INFORMATION AND COMMUNICATION TECHNOLOGY (ICT)

STANDARDS

The Section 508 standards established by the Access Board are incorporated into, and made part of all VA orders, solicitations and purchase orders developed to procure ICT.

These standards are found in their entirety at: https://www.access-board.gov/guidelines-and-standards/communications-and-it/about-the-ict-refresh/final-rule/text-of-the-standards-and-guidelines. A printed copy of the standards will be supplied upon request.

Federal agencies must comply with the updated Section 508 Standards beginning on January 18, 2018. The Final Rule as published in the Federal Register is available from the Access Board: https://www.access-board.gov/guidelines-and-standards/communications-and-it/about-the-ict-refresh/final-rule.

The Contractor shall comply with “508 Chapter 2: Scoping Requirements” for all electronic ICT and content delivered under this contract. Specifically, as appropriate for the technology and its functionality, the Contractor shall comply with the technical standards marked here:

E205 Electronic Content – (Accessibility Standard -WCAG 2.0 Level A and AA Guidelines)

E204 Functional Performance Criteria

E206 Hardware Requirements

E207 Software Requirements

E208 Support Documentation and Services Requirements

2.2 COMPATABILITY WITH ASSISTIVE TECHNOLOGY

The standards do not require installation of specific accessibility-related software or attachment of an assistive technology device. Section 508 requires that ICT be compatible with such software and devices so that ICT can be accessible to and usable by individuals using assistive technology, including but not limited to screen readers, screen magnifiers, and speech recognition software.

2.3 ACCEPTANCE AND ACCEPTANCE TESTING

Deliverables resulting from this solicitation will be accepted based in part on satisfaction of the Section 508 Chapter 2: Scoping Requirements standards identified above.

The Government reserves the right to test for Section 508 Compliance before delivery.

The Contractor shall be able to demonstrate Section 508 Compliance upon delivery.

3.0 GENERAL REQUIREMENTS

3.1 VA TECHNICAL REFERENCE MODEL

The Contractor shall support the VA enterprise management framework. In association with the framework, the Contractor shall comply with OIT Technical Reference Model (VA TRM). The VA TRM is one component within the overall Enterprise Architecture (EA) that establishes a common vocabulary and structure for describing the information technology used to develop, operate, and maintain enterprise applications. Moreover, the VA TRM, which includes the Standards Profile and Product List, serves as a technology roadmap and tool for supporting OIT. Architecture & Engineering Services (AES) has overall responsibility for the VA TRM.

TRM compliance is not required for this SaaS acquisition.

3.2 SOCIAL SECURITY NUMBER (SSN) REDUCTION

The Contractor solution shall support the Social Security Number (SSN) Fraud Prevention Act (FPA) of 2017 which prohibits the inclusion of SSNs on any document sent by mail. The Contractor support shall also be performed in accordance with Section 240 of the Consolidated Appropriations Act (CAA) 2018, enacted March 23, 2018, which mandates VA to discontinue using SSNs to identify individuals in all VA information systems as the Primary Identifier. The Contractor shall ensure that any new IT solution discontinues the use of SSN as the Primary Identifier to replace the SSN with the Integrated Control Number (ICN) in all VA information systems for all individuals. The Contractor shall ensure that all Contractor delivered applications and systems integrate with the VA Master Person Index (MPI) for identity traits to include the use of the ICN as the Primary Identifier. The Contractor solution may only use a Social Security Number to identify an individual in an information system if and only if the use of such number is required to obtain information VA requires from an information system that is not under the jurisdiction of VA.

3.3 INTERNET PROTOCOL VERSION 6 (IPV6)

The Contractor solution shall support Internet Protocol Version 6 (IPv6) based upon the memo issued by the Office of Management and Budget (OMB) on November 19, 2020 (https://www.whitehouse.gov/wp-content/uploads/2020/11/M-21-07.pdf). IPv6 technology, in accordance with the USGv6 Program (https://www.nist.gov/programs-projects/usgv6-program/usgv6-revision-1), NIST Special Publication (SP) 500-267B Revision 1 “USGv6 Profile” (https://doi.org/10.6028/NIST.SP.500-267Br1), and NIST SP 800-119 “Guidelines for the Secure Deployment of IPv6” (https://doi.org/10.6028/NIST.SP.800-119), compliance shall be included in all IT infrastructures, application designs, application development, operational systems and sub-systems, and their integration. In addition to the above requirements, all devices shall support native IPv6 and dual stack (IPv6 / IPv4) connectivity without additional memory or other resources being provided by the Government, so that they can function in a mixed environment. All public/external facing servers and services (e.g.

web, email, DNS, ISP services, etc.) shall support native IPv6 and dual stack (IPv6 / IPv4) users and all internal infrastructure and applications shall communicate using native IPv6 and dual stack (IPv6 / IPv4) operations.

3.4 SOFTWARE AND LICENSING REQUIREMENTS

SaaS FedRAMP Requirements (If vendor is not FedRAMP authorized). Note: The following is VA’s Digital Transformation Center (DTC) required SaaS FedRAMP verbiage.

The information system solution selected by the Contractor shall comply with the Federal Information Security Management Act (FISMA).

The Contractor shall comply with FedRAMP requirements for Moderate Impact as mandated by Federal laws and policies, including making available any documentation, physical access, and logical access needed to support this requirement.

The Contractor shall provide a SaaS product as defined by the following criteria:

Software as a Service (SaaS) is an application delivery model in which the application is hosted on a cloud infrastructure outside the security boundary of VA and is provided to the Cloud Service Customer (CSC) over the internet. The CSC uses the SaaS offering via a thin-client interface, such as a web-browser or a program interface. The CSC subscribes to the SaaS offering and is only responsible for minor in-app customizations.

The Cloud Service Provider (CSP) offering the application is responsible for management of the application, safeguarding of data stored or processed by the application, and all elements of the underlying infrastructure. Additionally, the CSP is responsible for all on-going compliance.

In order to qualify as SaaS for use at VA, and to align with Federal Risk and Authorization Management Program (FedRAMP) requirements, the hosting for the offering must conform to the NIST 800-145 definition of Cloud Computing and thus contain following key characteristics:

On-Demand Self-Service: The CSP fully automates the provisioning of both the customer interface and the underlying cloud components of the SaaS offering. In some cases, to the CSP may provision internal resources manually, while providing the CSC an automated interface to request and track the service.

Broad Network Access: The SaaS capabilities are available over the internet or over a network that is available from all access points the CSC requires. The SaaS offering is accessible through common platforms (e.g., mobile phones, tablets, laptops, and workstations).

Resource Pooling: The computing infrastructure supporting the SaaS offering is shared among more than one CSC using a multi-tenant model, and resources are dynamically assigned depending on customer demand.

Rapid Elasticity: Computing capabilities are automatically provisioned and released in a manner that scales with customer demand. In some cases, the scaling of resources may not be fully automated, but it should be fast enough to support the needs of the CSC, which the CSC would have to define.

Measured Service: Resource usage, such as storage, processing, bandwidth, and user activity are measured and reported on in a manner that is relevant to the SaaS offering.

Following guidance from the Federal CIO, VA will utilize existing JAB ATO or agency ATO issued by another agency as a starting point for FedRAMP requirements. If neither of those exist, VA will sponsor The Cloud Service Provider for a FedRAMP Authorization. VA will be using the FedRAMP baselines as a starting point, since they are specifically tailored for cloud services.

The Contractor shall, where applicable, assist with the VA ATO Process to help achieve agency authorization of the cloud service or migrated application at the impact level required by VA to utilize the product. For this solution the required impact level is:

Moderate Impact.

The Contractor shall comply with FedRAMP requirements surrounding data location within the Continental United States. FedRAMP specifies data location requirements in the High Baseline as part of control SA-9 (5); however, FedRAMP does not provide or specify data location requirements for other baselines.

The Contractor shall complete a FedRAMP System Security Plan (SSP) and supporting documentation including required attachments within 75 calendar days after contract award. (If Data Security Categorization is High Impact, this will be due 94 calendar days after contract award.)

The Contractor shall work with a VA Subject Matter Expert to develop a specific system boundary diagram including any integration and connectivity components for VA use.

This will be known as the VA Implementation Diagram (VAID) and will demonstrate the proposed implementation of this system at VA. The Contractor shall complete this deliverable with VA within 10 calendar days of contract award.

The Contractor shall complete a Third-Party Assessment Organization (3PAO) Security Assessment Plan (SAP) within 90 calendar days after contract award. (If Data Security Categorization is High Impact, this will be due after 113 calendar days after contract award.)

The Contractor shall complete a 3PAO Security Assessment Report (SAR) within

90 calendar days after the SSP is accepted by VA. (If Data Security Categorization is High Impact, this will be due 113 calendar days after the SSP is accepted by VA.)

The Contractor shall work with VA Subject Matter Experts to test the validity of the Incident Response Plan (IRP) and ensure proper troubleshooting of issues that may arise. This should be completed within 30 calendar days of the SSP being delivered.

The Contractor shall afford VA access to the Contractor’s and Cloud Service Provider’s (CSP) facilities, installations, technical capabilities, operations, documentation, records, and databases.

If new or unanticipated vulnerabilities are discovered by either VA or the Contractor, or if existing safeguards have ceased to function, the discoverer shall immediately bring the situation to the attention of the other party in accordance with Addendum B, VA Information, and Information System Security/Privacy Language.

The Contractor shall comply with data management requirements.

Successful issuance of a VA ATO will be required before live VA data can be used in the system.

The Contractor shall participate in FedRAMP Continuous Monitoring activities as outlined by FedRAMP’s Continuous Monitoring Strategy Guide found on the FedRAMP website.

The Contractor shall participate in monthly Agency and FedRAMP Sustainment meetings following the granting of a VA ATO.

The Contractor shall provide continuous monitoring activities including, but not limited to scans, security artifacts, and monthly Plan of Action and Milestones (POAM) reports as outlined by VA and FedRAMP requirements.

FedRAMP Deliverables:

FedRAMP System Security Plan (SSP) and required Attachments

VA Implementation Diagram

3PAO Security Assessment Plan (SAP)

3PAO Security Assessment Report (SAR)

Plan of Action and Milestones Monthly Reports.

The Contractor shall be responsible for the provision of all software licenses and any associated licensing maintenance required for any development, delivery, integration, operation, and/or maintenance associated with its proposed application(s), software products, software solution, and/or system including, but not limited to, any and all application(s), software and/or software products that comprise, are a part of, or integrate with the Contractor’s proposed application(s), software products, software solution, and/or system for the life of any resulting contract.

ADDENDUM B VA INFORMATION AND INFORMATION SYSTEM

SECURITY/PRIVACY LANGUAGE

GENERAL

Contractors, Contractor personnel, Subcontractors, and Subcontractor personnel shall be subject to the same Federal laws, regulations, standards, and VA Directives and Handbooks as VA and VA personnel regarding information and information system security.

ACCESS TO VA INFORMATION AND VA INFORMATION SYSTEMS

a. A Contractor/Subcontractor shall request logical (technical) or physical access to VA information and VA information systems for their employees, Subcontractors, and affiliates only to the extent necessary to perform the services specified in the contract, agreement, or task order.

b. All Contractors, Subcontractors, and third-party servicers and associates working with VA information are subject to the same investigative requirements as those of VA appointees or employees who have access to the same types of information. The level and process of background security investigations for Contractors must be in accordance with VA Directive and Handbook 0710, Personnel Suitability and Security Program. The Office for Operations, Security, and Preparedness is responsible for these policies and procedures.

c. Contract personnel who require access to national security programs must have a valid security clearance. National Industrial Security Program (NISP) was established by Executive Order 12829 to ensure that cleared U.S. defense industry contract personnel safeguard the classified information in their possession while performing work on contracts, programs, bids, or research and development efforts. The Department of Veterans Affairs does not have a Memorandum of Agreement with Defense Security Service (DSS). Verification of a Security Clearance must be processed through the

Special Security Officer located in the Planning and National Security Service within the Office of Operations, Security, and Preparedness.

d. Custom software development and outsourced operations must be located in the U.S. to the maximum extent practical. If such services are proposed to be performed abroad and are not disallowed by other VA policy or mandates (e.g. Business Associate Agreement, Section 3G), the Contractor/Subcontractor must state where all non-U.S.

services are provided and detail a security plan, deemed to be acceptable by VA, specifically to address mitigation of the resulting problems of communication, control, data protection, and so forth. Location within the U.S. may be an evaluation factor.

e. The Contractor or Subcontractor must notify the CO immediately when an employee working on a VA system or with access to VA information is reassigned or leaves the Contractor or Subcontractor’s employ. The CO must also be notified immediately by the Contractor or Subcontractor prior to an unfriendly termination.

VA INFORMATION CUSTODIAL LANGUAGE

1. Information made available to the Contractor or Subcontractor by VA for the performance or administration of this contract or information developed by the Contractor/Subcontractor in performance or administration of the contract shall be used only for those purposes and shall not be used in any other way without the prior written agreement of VA. This clause expressly limits the Contractor/Subcontractor's rights to use data as described in Rights in Data - General, FAR 52.227-14(d) (1).

2. VA information should not be co-mingled, if possible, with any other data on the Contractors/Subcontractor’s information systems or media storage systems in order to ensure VA requirements related to data protection and media sanitization can be met. If co-mingling must be allowed to meet the requirements of the business need, the Contractor must ensure that VA information is returned to VA or destroyed in accordance with VA’s sanitization requirements. VA reserves the right to conduct on-site inspections of Contractor and Subcontractor IT resources to ensure data security controls, separation of data and job duties, and destruction/media sanitization procedures are in compliance with VA directive requirements.

3. Prior to termination or completion of this contract, Contractor/Subcontractor must not destroy information received from VA, or gathered/created by the Contractor in the course of performing this contract without prior written approval by VA. Any data destruction done on behalf of VA by a Contractor/Subcontractor must be done in accordance with National Archives and Records Administration (NARA) requirements as outlined in VA Directive 6300, Records and Information Management and its Handbook 6300.1 Records Management Procedures, applicable VA Records Control Schedules, and VA Handbook 6500.1, Electronic Media Sanitization. Self-certification by the Contractor that the data destruction requirements above have been met must be sent to the VA CO within 30 days of termination of the contract.

4. The Contractor/Subcontractor must receive, gather, store, back up, maintain, use, disclose and dispose of VA information only in compliance with the terms of the contract and applicable Federal and VA information confidentiality and security laws, regulations and policies. If Federal or VA information confidentiality and security laws, regulations and policies become applicable to VA information or information systems after execution of the contract, or if NIST issues or updates applicable FIPS or Special Publications (SP) after execution of this contract, the parties agree to negotiate in good faith to implement the information confidentiality and security laws, regulations and policies in this contract.

5. The Contractor/Subcontractor shall not make copies of VA information except as authorized and necessary to perform the terms of the agreement or to preserve electronic information stored on Contractor/Subcontractor electronic storage media for restoration in case any electronic equipment or data used by the Contractor/Subcontractor needs to be restored to an operating state. If copies are made for restoration purposes, after the restoration is complete, the copies must be appropriately destroyed.

6. If VA determines that the Contractor has violated any of the information confidentiality, privacy, and security provisions of the contract, it shall be sufficient grounds for VA to withhold payment to the Contractor or third party or terminate the contract for default or terminate for cause under Federal Acquisition Regulation (FAR) part 12.

7. If a VHA contract is terminated for cause, the associated Business Associate Agreement (BAA) must also be terminated and appropriate actions taken in accordance with VHA Directive 1605.05, Business Associate Agreements. Absent an agreement to use or disclose protected health information, there is no business associate relationship.

8. The Contractor/Subcontractor must store, transport, or transmit VA sensitive information in an encrypted form, using VA-approved encryption tools that are, at a minimum, FIPS 140-2 validated.

9. The Contractor/Subcontractor’s firewall and Web services security controls, if applicable, shall meet or exceed VA minimum requirements. VA Configuration Guidelines are available upon request.

10. Except for uses and disclosures of VA information authorized by this contract for performance of the contract, the Contractor/Subcontractor may use and disclose VA information only in two other situations: (i) in response to a qualifying order of a court of competent jurisdiction, or (ii) with VA prior written approval. The Contractor/Subcontractor must refer all requests for, demands for production of, or inquiries about, VA information and information systems to the VA CO for response.

11. Notwithstanding the provision above, the Contractor/Subcontractor shall not release VA records protected by Title 38 U.S.C. 5705, confidentiality of medical quality assurance records and/or Title 38 U.S.C. 7332, confidentiality of certain health records pertaining to drug addiction, sickle cell anemia, alcoholism or alcohol abuse, or infection with human immunodeficiency virus. If the Contractor/Subcontractor is in receipt of a court order or other requests for the above-mentioned information, that

Contractor/Subcontractor shall immediately refer such court orders or other requests to the VA CO for response.

12. For service that involves the storage, generating, transmitting, or exchanging of VA sensitive information but does not require Assessment and Authorization (A&A) or a Memorandum of Understanding-Interconnection Security Agreement (MOU-ISA) for system interconnection, the Contractor/Subcontractor must complete a Contractor Security Control Assessment (CSCA) on a yearly basis and provide it to the COR.

INFORMATION SYSTEM DESIGN AND DEVELOPMENT

1. Information systems that are designed or developed for or on behalf of VA at non-VA facilities shall comply with all VA directives developed in accordance with FISMA, HIPAA, NIST, and related VA security and privacy control requirements for Federal information systems. This includes standards for the protection of electronic PHI, outlined in 45 C.F.R. Part 164, Subpart C, information and system security categorization level designations in accordance with FIPS 199 and FIPS 200 with implementation of all baseline security controls commensurate with the FIPS 199 system security categorization (reference VA Handbook 6500, Risk Management Framework for VA Information Systems – Tier 3: VA Information Security Program, and the TIC Reference Architecture). During the development cycle a Privacy Impact Assessment (PIA) must be completed, provided to the COR, and approved by the VA Privacy Service in accordance with Directive 6508, Implementation of Privacy Threshold Analysis and Privacy Impact Assessment.

2. The Contractor/Subcontractor shall certify to the COR that applications are fully functional and operate correctly as intended on systems using the VA Federal Desktop Core Configuration (FDCC), and the common security configuration guidelines provided by NIST or VA. This includes Internet Explorer 11 configured to operate on Windows 10 and future versions, as required.

3. The standard installation, operation, maintenance, updating, and patching of software shall not alter the configuration settings from the VA approved and FDCC configuration. Information technology staff must also use the Windows Installer Service for installation to the default “program files” directory and silently install and uninstall.

4. Applications designed for normal end users shall run in the standard user context without elevated system administration privileges.

5. The security controls must be designed, developed, approved by VA, and implemented in accordance with the provisions of VA security system development life cycle as outlined in NIST Special Publication 800-37, Guide for Applying the Risk Management Framework to Federal Information Systems, VA Handbook 6500, Risk Management Framework for VA Information Systems – Tier 3: VA Information Security Program and VA Handbook 6500.5, Incorporating Security and Privacy in System Development Lifecycle.

6. The Contractor/Subcontractor is required to design, develop, or operate a System of Records Notice (SOR) on individuals to accomplish an agency function subject to the Privacy Act of 1974, (as amended), Public Law 93-579, December 31, 1974 (5 U.S.C. 552a) and applicable agency regulations. Violation of the Privacy Act may involve the imposition of criminal and civil penalties.

7. The Contractor/Subcontractor agrees to:

a. Comply with the Privacy Act of 1974 (the Act) and the agency rules and regulations issued under the Act in the design, development, or operation of any system of records on individuals to accomplish an agency function when the contract specifically identifies:

i. The Systems of Records (SOR); and

ii. The design, development, or operation work that the Contractor/Subcontractor is to perform;

b. Include the Privacy Act notification contained in this contract in every solicitation and resulting subcontract and in every subcontract awarded without a solicitation, when the work statement in the proposed subcontract requires the redesign, development, or operation of a SOR on individuals that is subject to the Privacy Act; and

c. Include this Privacy Act clause, including this subparagraph (c), in all subcontracts awarded under this contract which requires the design, development, or operation of such a SOR.

8. In the event of violations of the Act, a civil action may be brought against the agency involved when the violation concerns the design, development, or operation of a SOR on individuals to accomplish an agency function, and criminal penalties may be imposed upon the officers or employees of the agency when the violation concerns the operation of a SOR on individuals to accomplish an agency function. For purposes of the Act, when the contract is for the operation of a SOR on individuals to accomplish an agency function, the Contractor/Subcontractor is considered to be an employee of the agency.

a. “Operation of a System of Records” means performance of any of the activities associated with maintaining the SOR, including the collection, use, maintenance, and dissemination of records.

b. “Record” means any item, collection, or grouping of information about an individual that is maintained by an agency, including, but not limited to, education, financial transactions, medical history, and criminal or employment history and contains the person’s name, or identifying number, symbol, or any other identifying particular assigned to the individual, such as a fingerprint or voiceprint, or a photograph.

c. “System of Records” means a group of any records under the control of any agency from which information is retrieved by the name of the individual or by some identifying number, symbol, or other identifying particular assigned to the individual.

9. The vendor shall…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .