Sol_140G0224Q0128_Amd_0001.pdf

PDF 408 KB Posted

Attached to
Metrohm Ion Chromatography Systems Brand Name or E Federal contract opportunity
Solicitation number
140G0224Q0128
Issued by
Department of the Interior US Geological Survey Office of Acquisitions and Grants

About this file

This document is an amendment to a Request for Quotations (RFQ) issued by the U.S. Geological Survey (USGS) Office of Acquisitions and Grants for the procurement of five (5) Metrohm USA's 940 Professional IC Vario ONE/SeS/HPG System (Ion Chromatography Systems). The purpose of this amendment is to attach the Terms and Conditions of the RFQ.

The solicitation is set aside for small businesses under NAICS code 334516 (Analytical Laboratory Instrument Manufacturing) with a size standard of 1,000 employees. Vendors must be registered and active in the System for Award Management (SAM) to submit a quotation. The solicitation will utilize FAR Part 12 for the acquisition of commercial products and services, and FAR Part 13.5 for simplified procedures. The required delivery is for brand name ion chromatography systems, including installation, software, warranty, and training for the USGS National Water Quality Laboratory in Denver, CO.

View the file

Other files for this federal contract opportunity

Other files attached to Metrohm Ion Chromatography Systems Brand Name or E, newest first.
File Type Posted
Sol_140G0224Q0128.pdf PDF
Brand_Name_Justification_Redacted.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

(x)

140G0224Q0128 x x copies of the amendment; (b) By acknowledging receipt of this amendment on each copy of the offer submitted ; or (c) By separate letter or electronic communication which includes a reference to the solicitation and amendment numbers. FAILURE OF YOUR ACKNOWLEDGEMENT TO BE

RECEIVED AT THE PLACE DESIGNATED FOR THE RECEIPT OF OFFERS PRIOR TO THE HOUR AND DATE SPECIFIED MAY RESULT IN REJECTION OF YOUR

OFFER. If by virtue of this amendment you desire to change an offer already submitted , such change may be made by letter or electronic communication, provided each letter or electronic communication makes reference to the solicitation and this amendment, and is received prior to the opening hour and date specified.

x

GDB

DENVER CO 80225-0046

204 DENVER FEDERAL CENTER

PO BOX 25046

USGS OAG DENVER ACQUISITION BRANCH

06/21/20240001

13. THIS ITEM ONLY APPLIES TO MODIFICATION OF CONTRACTS/ORDERS. IT MODIFIES THE CONTRACT/ORDER NO. AS DESCRIBED IN ITEM 14.

12. ACCOUNTING AND APPROPRIATION DATA (If required) is not extended.is extended, Items 8 and 15, and returning

Offers must acknowledge receipt of this amendment prior to the hour and date specified in the solicitation or as amended , by one of the following methods: (a) By completing

The above numbered solicitation is amended as set forth in Item 14. The hour and date specified for receipt of Offers

11. THIS ITEM ONLY APPLIES TO AMENDMENTS OF SOLICITATIONS

FACILITY CODE CODE

10B. DATED (SEE ITEM 13)

10A. MODIFICATION OF CONTRACT/ORDER NO.

9B. DATED (SEE ITEM 11)

9A. AMENDMENT OF SOLICITATION NO.

CODE

8. NAME AND ADDRESS OF CONTRACTOR (No., street, county, State and ZIP Code)

7. ADMINISTERED BY (If other than Item 6)CODE 6. ISSUED BY

PAGE OF PAGES

4. REQUISITION/PURCHASE REQ. NO.3. EFFECTIVE DATE2. AMENDMENT/MODIFICATION NO. 5. PROJECT NO. (If applicable)

1. CONTRACT ID CODE

AMENDMENT OF SOLICITATION/MODIFICATION OF CONTRACT

06/21/2024

CHECK ONE A. THIS CHANGE ORDER IS ISSUED PURSUANT TO: (Specify authority) THE CHANGES SET FORTH IN ITEM 14 ARE MADE IN THE CONTRACT

B. THE ABOVE NUMBERED CONTRACT/ORDER IS MODIFIED TO REFLECT THE ADMINISTRATIVE CHANGES (such as changes in paying office, C. THIS SUPPLEMENTAL AGREEMENT IS ENTERED INTO PURSUANT TO AUTHORITY OF:

D. OTHER (Specify type of modification and authority) appropriation data, etc.) SET FORTH IN ITEM 14, PURSUANT TO THE AUTHORITY OF FAR 43.103(b).

E. IMPORTANT: Contractor is not is required to sign this document and return __________________ copies to the issuing office.

ORDER NO. IN ITEM 10A.

14. DESCRIPTION OF AMENDMENT/MODIFICATION (Organized by UCF section headings, including solicitation/contract subject matter where feasible.)

Metrohm USA's 940 Professional IC Vario ONE/SeS/HPG System (Ion Chromatography Systems)

1. This is a Combined/Synopsis Solicitation issued as a Request for Quotations (RFQ).

Submit written quotations on RFQ Number 140G0224Q0128. This solicitation will utilize the policies in the Federal Acquisition Regulations (FAR) Part 12, Acquisition of Commercial

Products and Commercial Services, and in conjunction with the policies and procedures for evaluation, and award prescribed in FAR Part 13.5 Simplified Procedures for Certain

Commercial Items, as appropriate for this acquisition.

2. The solicitation document and incorporated provisions and clauses are those in effect through Federal Acquisition Circular (FAC) 2024-05.

Continued ...

16A. NAME AND TITLE OF CONTRACTING OFFICER (Type or print)15A. NAME AND TITLE OF SIGNER (Type or print)

15C. DATE SIGNED 16B. UNITED STATES OF AMERICA 15B. CONTRACTOR/OFFEROR 16C. DATE SIGNED

(Signature of person authorized to sign) (Signature of Contracting Officer)

Lisa Williams

STANDARD FORM 30 (REV. 11/2016)

Prescribed by GSA FAR (48 CFR) 53.243

Previous edition unusable

Except as provided herein, all terms and conditions of the document referenced in Item 9 A or 10A, as heretofore changed, remains unchanged and in full force and effect .

ITEM NO. SUPPLIES/SERVICES QUANTITY UNIT UNIT PRICE AMOUNT

NAME OF OFFEROR OR CONTRACTOR

2 51

CONTINUATION SHEET

REFERENCE NO. OF DOCUMENT BEING CONTINUED PAGE OF

(A) (B) (C) (D) (E) (F)

140G0224Q0128/0001

3. The solicitation is a 100% Small Business

Set-Aside. The North American Industry

Classification System (NAICS) code is 334516

(Analytical Laboratory Instrument Manufacturing) and the size standard is 1,000 employees.

4. Vendors are required to be registered and active in System for Award Management (SAM) when submitting an offer or quotation. Register at https://www.sam.gov/index.html prior to submitting your quotation. See FAR provision

52.204-7.

The purpose of this amendment is to attach the

Terms and Conditions of the RFQ.

NSN 7540-01-152-8067 OPTIONAL FORM 336 (4-86)

Sponsored by GSA

FAR (48 CFR) 53.110

Combined/Synopsis Solicitation 140G0224Q0128

Table of Contents

Brand Name Specifications/Requirements Contractor Performance Assessment Reporting System (DEC 2015) DOI ELECTRONIC INVOICING Electronic Invoicing and Payment Requirements - Invoice Processing Platform (IPP) (FEB 2021) FISMA Information Technology Security Requirements Summary ICT Accessibility Requirements Statement per the Revised Section 508 of the Rehabilitation Act INTERNET PROTOCOL version 6 (June 2012) GS0199 Prevention of Malicious Code (JUN 2018) GS0231 Technical Liaison -Technical Direction (JUL 2018) GS1101 Contract Administration Office. (JUL 2001) GS1131 Unilateral Deobligation of Unexpended Funds. (MAY 2013) GS1376 Software Licensing Agreements JUL 2001 52.212-5 Contract Terms and Conditions Required To Implement Statutes or Executive Orders - Commercial Products and Commercial Services. (MAY 2024) 52.252-2 Clauses Incorporated by Reference. (FEB 1998) GS2101 Inquiries (FEB 2007) GS2115 Independent Review of Protests to the Agency (MAY 2024) 52.204-24 Representation Regarding Certain Telecommunications and Video Surveillance Services or Equipment. (NOV 2021) 52.204-26 Covered Telecommunications Equipment or Services-Representation. (OCT 2020) 52.204-29 Federal Acquisition Supply Chain Security Act Orders-Representation and Disclosures. (DEC 2023) 52.209-11 Representation by Corporations Regarding Delinquent Tax Liability or a Felony Conviction under any Federal Law. (FEB 2016) 52.212-3 Offeror Representations and Certifications-Commercial Products and Commercial Services. (MAY 2024) 52.219-1 Small Business Program Representations. (FEB 2024) 52.222-22 Previous Contracts and Compliance Reports. (FEB 1999) 52.222-25 Affirmative Action Compliance. (APR 1984) 52.229-11 Tax on Certain Foreign Procurements-Notice and Representation. (JUN 2020) 52.233-2 Service of Protest Department of the Interior (Jul 1996) (Deviation) Basis for Award Instructions to Vendors Electronic Submission of Quotations – Required Questions – Cutoff 52.252-1 Solicitation Provisions Incorporated by Reference. (FEB 1998)

Clauses:

Brand Name Specifications/Requirements

A. Introduction:

The U.S. Geological Survey (USGS), National Water Quality Laboratory (NWQL), Denver, CO has a requirement to purchase five (5) new Metrohm USA’s 940 Professional IC Vario ONE/SeS/HPG System (Ion Chromatography Systems), which shall include installation of the system at the National Water Quality Laboratory (NWQL), all required software, warranty, and training of NWQL staff.

B. Background:

Ion chromatography systems (ICs) are currently used at the National Water Quality Laboratory (NWQL) to measure environmental water samples for concentrations of bromide, fluoride, chloride and sulfate. The NWQL currently has one (1) IC dedicated to bromide analysis and 3 other ICs which analyzes approximately a total of 32,000 tests for FY23. The ion chromatography instruments currently used for these analyses range in age and have started to show signs of decreasing reliability and are or will no longer be covered under a maintenance service contract by the end of CY24.

C. Manufacturer:

Brinkmann Instruments, Inc.

DBA: Metrohm USA Inc.

www.metrohmusa.com

D. Brand Name Specifications: Five (5) New Metrohm USA’s 940 Professional IC Vario ONE/SeS/HPG System (Ion Chromatography Systems) (Mfg. Part Number: 29401440 and associated components:

1. 940 Professional IC Vario ONE/SeS/HPG unit (Part No. 29401440):

o Sequential suppression.

o Binary high-pressure gradient.

o 800 Dosino used for the regeneration of the suppressor.

2. ProfIC Conductivity Detector (Part No. 28509010):

o Microprocessor-controlled Digital Signal Processing.

o 1 – 15000 µS/cm measuring range with < 0.1 nS at 1 µS/cm noise.

o < 0.1% for conductivity values higher than 16 µS/cm and <1% for values lower than 16 µS/cm.

o Drift <0.2 nS/cm per hour.

o 0.8 µL cell volume.

o 5.0 MPa (50 bar) maximum operating pressure.

o Cell temperature 20-50ºC with temperature compensation and <30 min heating time.

3. Includes MSM-A Rotor (Part No. 62832000).

o Suppression rotor 32 mm.

o Adapter sleeve f. Suppressor D22 Vario (Part No. 62842020) for easy installation of rotor.

4. IC Equipment: Dosino Regeneration (Part No. 65330190):

o Accessory Set for the Assembly of a Dosino for automatic regeneration of the MSM (includes bottle attachment GL 45 for eluents and reagents with connectors for the adsorber tube and the aspiration tubing), Adapter SGJ 14 for 6.1619.XXX absorber tube for dilution sample processor, thread adapter S 40 to GL45 for bottles with S40 thread, and FEP tubing /M6/100 cm with light and kink protection.

http://www.metrohmusa.com/

5. 800 Dosino (Part No. 28000010):

o Drive with write/ready hardware for intelligent dosing units with 150 cm fixed cable.

6. 858 ProfIC Sample Processor Autosampler (Part No. 28580010):

o Can process samples from 500 µL to 500 mL.

o Processes samples using a peristaltic pump on the IC system or with 800 Dosino.

7. Sample Rack (Part No. 62041440):

o 148 x 11 mL samples with 3 rinsing beakers.

8. Accessory Set (Part No. 605330010):

o Accessory set for inline ultrafiltration 2 in the pull mode.

o For use with the 858 professional sample processor and the 919 autosampler plus.

9. 941 Eluent Production Module (Part No. 29410010):

o Enables automatic production of up to four inline eluents.

o Enables continuous working with manual intervention.

o Guarantees stable retention times.

10. MagIC Net4.X Compact Upgrade to Professional Software License (PN 66059406).

11. In Vial Dilution (MiVDT) System which includes:

o Washing Station for the IC (PN 62841100).

o T Connector for M6 (PN 61808060).

o Coupling Outer M6/UNF (PN 62744080).

o Adaptor UNF 10//32 Ext./M6 Int. PEEK (PN 62744200).

o Dosing Unit 807 Glass 10 and Glass 2 (PN 63032210 and 63032120):

▪ Includes integrated data chip with 10 mL glass cylinder or 2 mL glass cylinder and light protection.

▪ Mountable to a reagent bottle with ISO/DIN GL 45 glass thread.

▪ Includes FEP tubing connection and antidiffusion tip.

o PTFE Caps 1/16 In/0.97mm 5 m and 1/16 In/0.5mm 3 m (PN 61803020 and 61803030).

o FEP Tubing connection M5 150 and M6 18 (PN 61805030 and 61805050).

o Eluent bottle cap GL45 (PN 61602160).

o Thread adaptors S40/GL45 and 40 mm/GL45 (PN 61618020 and 61618050).

o PE Canister 10L (PN 61621000).

o Adapter Dosino Port 4/M6 with FEP tubing connection M6 for 845 85 cm (PN 61808280 and

61838010).

o Dosino holder for 850/881 (PN 62057210).

o Needle holder for 1/8 In/M6 for 838 (PN 62833020).

o Adaptor for Aspiration Filter for 850 (62744210).

o Trans. Tubing 10mL 2xM6 with holder for SP (PN 61562130).

o 2 Dosinos (PN 28000010).

12. Metrosep A Supp 19-150/4.0 column and Metrosep A Supp 19 Guard/4.0 (PN 601034420 and 601034500).

Additional Requirements:

1. Installation and comprehensive multi-day IC training for up to 4 NWQL employees.

2. Performance Maintenance for ProfIC Dual IC Pump, Autosampler, Extension Modules, and Buret and Drive Combo twice a year.

3. At a minimum 1 (one) year manufacturing warranty: which covers all hardware components of the instrument and the labor for the component repair. For all critical repairs, hardware components are to be shipped back to the factory for detailed inspection and troubleshooting. Warranty period starts from the time of acceptance.

4. The vendor shall provide either hard or electronic copies of the user manual and warranty details, software that is downloadable or on a disk, and results of any factory tests completed prior to installation.

5. After installation, the vendor shall deliver a report that describes the services performed, on-site instrument performance, and documentation verifying the system is operating to the manufacturer’s specifications.

(End of Brand Name Specifications/Requirements)

Contractor Performance Assessment Reporting System (DEC 2015)

1) FAR 42.1502 directs all Federal agencies to collect past performance information on contracts. The Department of the Interior (DOI) has implemented the Contractor Performance Assessment Reporting System (CPARS) to comply with this regulation. One or more past performance evaluations will be conducted in order to record your contract performance as required by FAR 42.15.

2) The past performance evaluation process is a totally paperless process using CPARS. CPARS is a web-based system that allows for electronic processing of the performance evaluation report. Once the report is processed, it is available in the Past Performance Information Retrieval System (PPIRS) for Government use in evaluating past performance as part of a source selection action.

3) We request that you furnish the Contracting Officer (CO) with the name, position title, phone number, and email address for each person designated to have access to your firm's past performance evaluation(s) for the contract no later than 30 days after award. Each person granted access will have the ability to provide comments in the Contractor portion of the report and state whether or not the Contractor agrees with the evaluation, before returning the report to the Assessing Official (AO).

Information in the report must be protected as source selection sensitive information not releasable to the public.

4) When your Contractor Representative(s) are registered in CPARS, they will receive an automatically generated email with detailed login instructions. Further details, systems requirements, and training information for CPARS is available at https://www.cpars.gov/.

5) Within 60 days after the end of a performance period, the AO will complete an interim or final past performance evaluation, and the report will be accessible at https://www.cpars.gov/.

a) Contractor Representatives may then provide comments in response to the evaluation, or return the evaluation without comment.

b) Your comments should focus on objective facts in the AO's narrative and should provide your views on the causes and ramifications of the assessed performance.

c) All information provided should be reviewed for accuracy prior to submission.

d) If you elect not to provide comments, please acknowledge receipt of the evaluation by indicating "No comment" in the space provided, and then selecting “Accept the Ratings and Close the Evaluation”.

e) Your response is due within 60 calendar days after receipt of the CPAR. On day 15, the evaluation will become available in PPIRS-RC marked as “Pending” with or without comments and whether or not it has been closed.

https://www.acquisition.gov/sites/default/files/current/far/html/Subpart%2042_15.html https://www.acquisition.gov/sites/default/files/current/far/html/Subpart%2042_15.html https://www.cpars.gov/ https://www.cpars.csd.disa.mil/ https://www.cpars.gov/

f) If you do not sign and submit the CPAR within 60 days, it will automatically be returned to the Government and will be annotated: "The report was delivered/received by the contractor on (date). The contractor neither signed nor offered comment in response to this assessment."

6) The following guidelines apply concerning your use of the past performance evaluation:

a) Protect the evaluation as source selection information. After review, transmit the evaluation by completing and submitting the form through CPARS. If for some reason you are unable to view and/or submit the form through CPARS, contact the CO for instructions.

b) Strictly control access to the evaluation within your organization. Ensure the evaluation is never released to persons or entities outside of your control.

c) Prohibit the use of or reference to evaluation data for advertising, promotional material, pre-award surveys, responsibility determinations, production readiness reviews, or other similar purposes.

7) If you wish to discuss a past performance evaluation, you should request a meeting in writing to the CO no later than seven days following your receipt of the evaluation. The meeting will be held in person or via telephone or other means during your 60-day review period.

8) A copy of the completed past performance evaluation will be available in CPARS for your viewing and for Government use supporting source selection actions after it has been finalized.

DOI ELECTRONIC INVOICING Electronic Invoicing and Payment Requirements - Invoice Processing Platform (IPP) (FEB 2021)

Payment requests must be submitted electronically through the U. S. Department of the Treasury's Invoice Processing Platform System (IPP).

'Payment request' means any request for contract financing payment or invoice payment by the Contractor. To constitute a proper invoice, the payment request must comply with the requirements identified in the applicable Prompt Payment clause included in the contract, or the clause 52.212-4 Contract Terms and Conditions - Commercial Items included in commercial item contracts. The IPP website address is: https://www.ipp.gov.

Under this contract, the following documents are required to be submitted as an attachment to the IPP invoice:

A copy of the Contractor’s internally generated invoice.

The Contractor must use the IPP website to register access and use IPP for submitting requests for payment. The Contractor Government Business Point of Contact (as listed in SAM) will receive enrollment instructions via email from the Federal Reserve Bank of St. Louis (FRBSTL) within 3 - 5 business days of the contract award date. Contractor assistance with enrollment can be obtained by contacting the IPP Production Helpdesk via email IPPCustomerSupport@fiscal.treasury.gov or phone (866) 973-3131.

If the Contractor is unable to comply with the requirement to use IPP for submitting invoices for payment, the Contractor must submit a waiver request in writing to the Contracting Officer with its proposal or quotation.

FISMA Information Technology Security Requirements Summary

COTS

Hardware or Software

Development or Maintenance of Custom Applications

Outsourced IT Services or On-site Support

Requirements herein are incorporated as part the Statement of Work/ Performance Work Statement:

1 N/A Background Investigations.

The Contractor shall perform in accordance with clause “Security Requirements: Facility Access and Information Technology.”

2 N/A

Contractor will have access to Privacy Act System of Records - Work under this contract will involve design, development or operation of (access to) system(s) of records containing personal information protected by the Privacy Act (5 U.S.C. Section 552a).

Non-disclosure Agreement.

Prior to receiving access to USGS computers, contractor employees shall be required to sign nondisclosure or other system security agreements, depending on the systems to be used and level of access granted.

Applies whenever any contractor employee has unsupervised access to a USGS system (even if only basic network, internet or email or will develop custom applications) such as:

• User Access to USGS IT Systems known to contain sensitive or proprietary data

• IT Support services (greater than user access)

• Development or Maintenance of Custom Applications

• On-site contractor support and management of IT system

• Off-site contractor Oversight and Management of IT

System

• IT Security Services

Privacy Act System: [Identify covered system(s) to which the contractor may have access]

Work to be performed: [Summarize nature of the contractor's use of such records, such as]

• User-level access to system containing protected records

• Operation or maintenance of Privacy Act System of records or computers hosting such system

• Design or modification of a Privacy Act system of records]

The contractor is not required or permitted to respond to requests for Privacy Act data or to make decisions about releases of data under the Act. Contractor shall ensure its employees are instructed to safeguard against improper use or release of such data and advise them that violation of the Act may involve criminal penalties. The contractor will comply with FAR clause 52.224-2, Privacy Act, incorporated herein by reference and with DOI Privacy Act regulations at 43 CFR 2, Subpart D

COTS

Hardware or Software

Development or Maintenance of Custom Applications

Outsourced IT Services or On-site Support

Requirements herein are incorporated as part the Statement of Work/ Performance Work Statement:

3 N/A Training.

The Contractor shall perform in accordance with clause “Security Requirements: Facility Access and Information Technology” - Contractor employees must successfully complete DOI’s end-user computer security awareness training prior to being granted access to DOI data or being issued a user account. Training must be renewed annually. Additionally, the contract employees must sign a Statement of Responsibility (SOR) that states they have read the appropriate Rules of Behavior and other applicable Information security policies.

4 N/A Personnel Changes.

The Contractor shall perform in accordance with clause “Security Requirements: Facility Access and Information Technology” - The contractor must notify the COR immediately when an employee working on a DOI system is reassigned or leaves the contractor’s employ.

Applies whenever any contractor employee has unsupervised access to a USGS system (even if only basic network, internet or email or will develop custom applications) such as:

• User Access to USGS IT Systems known to contain sensitive or proprietary data

• IT Support services (greater than user access)

• Development or Maintenance of Custom Applications

• On-site contractor support and management of IT system

• Off-site contractor Oversight and Management of IT

System

• IT Security Services *

*May not be applicable for off-site performance.

5 N/A Contractor Location.

The Contractor shall perform in accordance with clause “Security Requirements: Facility Access and Information Technology.”

Applies whenever any contractor employee has unsupervised access to a USGS system (even if only basic network, internet or email or will develop custom applications) such as:

• User Access to USGS IT Systems known to contain sensitive or proprietary data

• IT Support services (greater than user access)

• Development or Maintenance of Custom Applications

• On-site contractor support and management of IT system

COTS

Hardware or Software

Development or Maintenance of Custom Applications

Outsourced IT Services or On-site Support

Requirements herein are incorporated as part the Statement of Work/ Performance Work Statement:

• Off-site contractor Oversight and Management of IT System

• IT Security Services No portion of the services to be performed hereunder may be performed outside the United States without the express written permission of the Contracting Officer.

If services are proposed to be performed abroad, the Contractor shall provide an acceptable security plan that addresses mitigation of problems related to communication, control, and protecting the confidentiality, integrity, and availability of IT systems and information.

A Security Plan Template is available upon request from the Contracting Officer.

6 N/A N/A Applicable Standards.

The Contractor shall perform in accordance with clause “Security Requirements: Facility Access and Information Technology” - Contractor must follow the DOI System Development Life Cycle (SDLC), NIST SP 800-64 and the DOI SDLC Security Integration Guide.

7 N/A Asset Valuation-Security Categorization:

The Contractor shall perform in accordance with clause “Security Requirements: Facility Access and Information Technology.”

User Access to USGS IT Systems

– The Government is responsible for security categorization on USGS systems to which the Contractor may have access under this contract.

IT Support Services greater than User-Level Services Choose one:

The Government is responsible for security categorization on USGS systems to which the Contractor may have access under this contract.

- The Government has defined the [insert name of system to be developed, operated or maintained by the contractor] to be a [Major Application], [Minor Application] or [General support system] as defined in OMB Circular A-130, Appendix III and NIST SP800-53. The following risk and sensitivity levels have been assigned based on the FIPS 199 and the NIST SP 800-60.

Mission impact:

Data sensitivity:

Risk level:

https://insight.usgs.gov/aei/offices/oa/oag/AOP/guidefordevelopingsecurityplans.pdf

COTS

Hardware or Software

Development or Maintenance of Custom Applications

Outsourced IT Services or On-site Support

Requirements herein are incorporated as part the Statement of Work/ Performance Work Statement:

Bureau/departmental/national criticality:

Off-Site Oversight and Management of IT System- The Contractor shall use the FIPS 199 and the NIST SP 800- 60 to determine information types and security categorization based on mission impact, data sensitivity, risk level, and bureau / departmental / national criticality for Contractor-owned and operated systems used to provide services under this contract.

Solicitations must include either the complete publication or a reference to public facilities, such as a website or office, where it may be accessed.

IT Security Services - Applies only if the purpose of the contract includes obtaining asset valuation services.

The Contractor shall use the FIPS 199 and the NIST SP 800- 60 to determine information types and security categorization based on mission impact, data sensitivity, risk level, and bureau / departmental / national criticality for Contractor-owned and operated systems used to provide services under this contract.

Solicitations must include either the complete publication or a reference to public facilities, such as a website or office, where it may be accessed.

The Government shall be granted unlimited rights in software or data produced hereunder as described in FAR clause 52.227-17, Rights in Data— Special Works, incorporated by reference herein.

Select either COTS or custom software language as applicable. If both apply, identify software/data deliverables governed by each clause.

Property Rights.

1. For Federal Supply Schedule orders or orders under an existing contract, rights to software acquired hereunder are set forth in the basic contract.

2. For open market contracts, the Government's rights in software delivered hereunder shall be as described in software developer's commercial software license agreement or the clause FAR 52.227-19, Commercial Computer Software- Restricted Rights, whichever is greater.

9 N/A Independent Verification and Validation (IV&V).

The Government is responsible for independent software verification and validation prior to being moved into production.

On-Site Contractor Support and Management of IT System Choose one:

Software will be independently verified and validated by the Government or another selected contractor prior to being moved into production.

COTS

Hardware or Software

Development or Maintenance of Custom Applications

Outsourced IT Services or On-site Support

Requirements herein are incorporated as part the Statement of Work/ Performance Work Statement:

Contractor will ensure that independent verification and validation is performed on software deployed on contractor managed systems containing USGS data, in accordance with DOI SDLC Security Integration Guide

Off-Site Contractor Operation and Management of IT System- Contractor will ensure that independent verification and validation is performed on software deployed on contractor managed systems containing USGS data, in accordance with DOI SDLC Security Integration Guide

IT Security Service - Applies only if the purpose of the contract includes obtaining IV&V services.

10 N/A Applies if the purpose of the contract includes obtaining C&A services.

Certification & Accreditation.

User Access to USGS IT Systems or IT Supports Services (Greater than User Access Certification and Accreditation on USGS systems to which the Contractor may have access under this contract will be conducted by the Government or another of its contractors.

Development or Maintenance of Custom Applications The contractor will perform Certification and Accreditation (C&A) services on the application developed or maintained hereunder prior to going into production. The application must be re-accredited every three years or whenever there is a major change that affects security. C&A documents will be provided to the COR in both hard copy and electronic forms. The contractor must follow NIST SP 800-37, 800-18, 800- 30, 800-60, 800-53A, Federal Information Processing Standard (FIPS) 199 and 200, the associated DOI guides/templates, the DOI Security Test & Evaluation (ST&E) Guide, and the DOI Privacy Impact Assessment. NIST documents are available on the internet at http://csrc.nist.gov/publications/nistpubs/ FIPS documents are available on the internet at http://csrc.nist.gov/publications/nistpubs/. The contractor may request copies of DOI documents by contacting the Contracting Officer. The government reserves the right to conduct the ST&E using either Government personnel or an independent contractor.

The contractor will take immediate and timely action to correct or mitigate any weaknesses discovered as necessary to bring the application or system into compliance with the above requirement.

COTS

Hardware or Software

Development or Maintenance of Custom Applications

Outsourced IT Services or On-site Support

Requirements herein are incorporated as part the Statement of Work/ Performance Work Statement:

On-Site Contractor Support and Management of IT System or Off- Site Contractor Operation and Management of IT System The Contractor must maintain systems that are compliant with NIST SP 800-18, 800-30, 800-37, 800- 53A, 800-60, Federal Information Processing Standard (FIPS) 199 and 200, the associated DOI guides/templates, the DOI Security Test & Evaluation (ST&E) Guide, and the DOI Privacy Impact Assessment. As required by the above, Major Applications and General Support Systems shall be certified and accredited (C&A) prior to going into production and re-accredited every three years or whenever there is a major change that affects security.

C&A documents will be provided to the COR in both hard copy and electronic forms. NIST documents are available on the internet at http://csrc.nist.gov/publications/nistpubs/. The contractor may request copies of DOI documents by contacting the Contracting Officer. The government will reserve the right to conduct the ST&E, using either Government personnel or an independent contractor.

The contractor will take immediate and timely action to correct or mitigate any weaknesses discovered as necessary to bring the application or system into compliance with the above requirement.

11 N/A for COTS

HW & SW,

User Access to

USGS IT

Systems (other than IT services), IT Support Services (User Level or greater access)

N/A Internet Logon Banner.

The Contractor shall perform in accordance with clause “Security Requirements: Facility Access and Information Technology.”

Development or Maintenance of Custom Applications OR On-Site Contractor Support and Management of IT System OR Off-site Contractor Oversight and Management of IT System- Web-based applications developed or maintained under this contract must contain a USGS approved logon banner:

https://portal.doi.net/CIO/ITPMgmt/Documents/IT Standards/IT Security/DOI Security Control Standards (based on NIST SP 800-53 Revision 3)/Access Control v1.4.pdf

12 N/A Incident Reporting.

The Contractor shall perform in accordance with contract clause “Security Requirements: Facility Access and Information Technology” - The contractor must report computer security incidents affecting DOI data or systems in accordance with the DOI Computer Incident Response Guide.

https://portal.doi.net/CIO/ITPMgmt/Documents/IT%20Standards/IT%20Security/DOI%20Security%20Control%20Standards%20(based%20on%20NIST%20SP%20800-53%20Revision%203)/Access%20Control%20v1.4.pdf https://portal.doi.net/CIO/ITPMgmt/Documents/IT%20Standards/IT%20Security/DOI%20Security%20Control%20Standards%20(based%20on%20NIST%20SP%20800-53%20Revision%203)/Access%20Control%20v1.4.pdf https://portal.doi.net/CIO/ITPMgmt/Documents/IT%20Standards/IT%20Security/DOI%20Security%20Control%20Standards%20(based%20on%20NIST%20SP%20800-53%20Revision%203)/Access%20Control%20v1.4.pdf https://portal.doi.net/CIO/ITPMgmt/Documents/IT%20Standards/IT%20Security/DOI%20Security%20Control%20Standards%20(based%20on%20NIST%20SP%20800-53%20Revision%203)/Access%20Control%20v1.4.pdf

COTS

Hardware or Software

Development or Maintenance of Custom Applications

Outsourced IT Services or On-site Support

Requirements herein are incorporated as part the Statement of Work/ Performance Work Statement:

13 Quality Control.

All software or hardware purchased must be free of malicious code such as viruses, Trojan horse programs, worms, spyware, etc. Validation of this must be written into the contract.

14 N/A N/A Self-Assessment.

The Contractor shall perform in accordance with contract clause “Security Requirements: Facility Access and Information Technology” - The contractor must conduct an annual self-assessment in accordance with annual DOI guidance on all information systems in production.

15 N/A Vulnerability Analysis.

Vulnerability Analysis on USGS systems to which the Contractor may have access under this contract will be conducted by the Government or another of its contractors.

16 N/A Logon Banner.

Contractor employees who access DOI information systems must acknowledge a government-approved legal warning banner prior to logging on to the system.

This includes contractor owned information systems hosting DOI data.

17 N/A Security Controls.

The Contractor shall perform in accordance with contract clause “Security Requirements: Facility Access and Information Technology” – The Contractor shall ensure compliance with the security control requirements of the current version of NIST SP 800-53, Rev.1, which are applicable to the security categorization of the data or system. FIPS 199 and the NIST SP 800-60 will be used to determine information types and security categorizations.

18 N/A N/A Contingency Plan.

The Contractor shall perform in accordance with contract clause “Security Requirements: Facility Access and Information Technology.”

For IT Support Services: The Contractor shall submit a contingency plan in accordance with NIST SP 800-34 and DOI IT Systems Contingency Plan Guide.

ICT Accessibility Requirements Statement per the Revised Section 508 of the Rehabilitation Act

Ion Chromatographs

E201.1 Scope ICT that is procured, developed, maintained, or used by agencies shall conform to the Revised 508 Standards.

E205.1 General Electronic content shall comply with E205.

E205.2 Public Facing Electronic content that is public facing shall conform to the accessibility requirements specified in E205.4.

E205.3 Agency Official Communication Electronic content that is not public facing shall conform to the accessibility requirements specified in E205.4 when such content constitutes official business and is communicated by an agency through one or more of the following:

● A. An emergency notification;

● B. An initial or final decision adjudicating an administrative claim or proceeding;

● C. An internal or external program or policy announcement;

● D. A notice of benefits, program eligibility, employment opportunity, or personnel action;

● E. A formal acknowledgement of receipt;

● F. A survey questionnaire;

● G. A template or form;

● H. Educational or training materials; or

● I. Intranet content designed as a Web page.

E205.4 Accessibility Standard (WCAG 2.0) - Electronic content shall conform to Level A and Level AA Success Criteria and Conformance Requirements in WCAG 2.0 (Incorporated by reference, see 702.10.1).

E206.1 General. Where components of ICT are hardware and transmit information or have a user interface, such components shall conform to the requirements in Chapter 4.

E208.1 General Where an agency provides support documentation or services for ICT, such documentation and services shall conform to the requirements in Chapter 6.

E301 General

E301.1 Scope. The requirements of Chapter 3 shall apply to ICT where required by 508 Chapter 2 (Scoping Requirements), 255 Chapter 2 (Scoping Requirements), and where otherwise referenced in any other chapter of the Revised 508 Standards or Revised 255 Guidelines.

E302 Functional Performance Criteria

302.1 Without Vision. Where a visual mode of operation is provided, ICT shall provide at least one mode of operation that does not require user vision.

302.2 With Limited Vision. Where a visual mode of operation is provided, ICT shall provide at least one mode of operation that enables users to make use of limited vision.

302.3 Without Perception of Color. Where a visual mode of operation is provided, ICT shall provide at least one visual mode of operation that does not require user perception of color.

302.4 Without Hearing. Where an audible mode of operation is provided, ICT shall provide at least one mode of operation that does not require user hearing.

302.5 With Limited Hearing. Where an audible mode of operation is provided, ICT shall provide at least one mode of operation that enables users to make use of limited hearing.

302.6 Without Speech. Where speech is used for input, control, or operation, ICT shall provide at least one mode of operation that does not require user speech.

302.7 With Limited Manipulation. Where a manual mode of operation is provided, ICT shall provide at least one mode of operation that does not require fine motor control or simultaneous manual operations.

302.8 With Limited Reach and Strength. Where a manual mode of operation is provided, ICT shall provide at least one mode of operation that is operable with limited reach and limited strength.

302.9 With Limited Language, Cognitive, and Learning Abilities. ICT shall provide features making its use by individuals with limited cognitive, language, and learning abilities simpler and easier.

503.1 General Applications shall conform to 503.

603.1 General. ICT support services including, but not limited to, help desks, call centers, training services, and automated self-service technical support, shall conform to 603.

603.2 Information on Accessibility and Compatibility Features. ICT support services shall include information on the accessibility and compatibility features required by 602.2.

603.3 Accommodation of Communication Needs. Support services shall be provided directly to the user or through a referral to a point of contact. Such ICT support services shall accommodate the communication needs of individuals with disabilities.

INTERNET PROTOCOL version 6 (June 2012)

1. Any system hardware, software, firmware and/or networked component (voice, video or data) developed, procured, or acquired in support and/or performance of this contract shall be capable of transmitting, receiving, processing, forwarding and storing digital information across system boundaries utilizing system packets that are formatted in accordance with commercial standards of Internet Protocol (IP) version 6 (IPv6) as set forth in the USGv6 Profile (NIST Special Publication 500-267) and corresponding declarations of conformance defined in the USGv6 Test Program. In addition, this system shall maintain interoperability with IPv4 systems and provide at least the same level of performance and reliability capabilities of IPv4 products.

2. Specifically, any new IP product or system developed, acquired, or produced must:

a. Interoperate with both IPv6 and IPv4 systems and products, and

b. Have available contractor/vendor IPv6 technical support for development and implementation and fielded product management.

3. As IPv6 evolves, the Contractor commits to upgrading or providing an appropriate migration path for each item developed, delivered or utilized at no additional cost to 'the Government. The Contractor shall retrofit all non-IPv6 capable equipment, as defined above, that is fielded under this contract with IPv6 capable equipment, at no additional cost to the Government.

4. The contractor shall provide technical support for both IPv4 and IPv6.

5. Any system or software must be able to operate on networks supporting IPv4, IPv6 or one that supports both.

6. Any product whose non-compliance is discovered and made known to the Contractor within one year after acceptance shall be upgraded, modified or replaced to bring it into compliance at no additional cost to the Government.

GS0199 Prevention of Malicious Code (JUN 2018)

(a) Definitions

Malicious code is a computer code developed for the purpose of causing some form of intentional damage to computer systems or networks. Malicious code may be a complete program or code imbedded in software programs that appear to provide useful functions. The term includes computer viruses and other destructive programs, such as "Trojan Horses" and network "worms."

(b) The contractor must have in place an anti-virus procedure to ensure that media supplied is uncontaminated by malicious code.

(c) The contractor is required to scan all delivered software to insure it is free of malicious code prior to its installation or operation on USGS-owned computers or contractor-owned computers connected to USGS computer systems or networks. Contractors using diagnostics software disks or connecting to a non-USGS computer while performing repairs or upgrades to a USGS computer will scan the serviced computer's drive(s) to insure they are free of malicious code upon completion of the service call, or prior to return of serviced equipment, if servicing is performed off-site.

GS0231 Technical Liaison -Technical Direction (JUL 2018)

a) The performance required herein shall be subject to the technical direction of the Technical Liaison (TL) as identified below. As used herein, "technical direction" is defined as direction to the contractor that fills in details, suggests possible lines of approach, or otherwise supplements the scope of the work set forth herein and shall not constitute a new assignment, and does not supersede or modify any article or clause of this contract.

b) The Technical Liaison is not authorized to perform, formally or informally, any of the following actions:

(1) Promise, award, agree to award, or execute any contract, contract modification, or notice of intent that changes or may change this contract;

(2) Waive or agree to modification of the delivery schedule;

(3) Make any final decision on any contract matter subject to the Disputes Clause;

(4) Terminate, for any reason, the contractor's right to proceed;

(5) Obligate in any way, the payment of money by the Government. Only a warranted Contracting Officer is authorized to obligate funds on this or any other contract action.

(c) The contractor shall immediately notify the Contracting Officer in writing if the Technical Liaison has taken an action (or fails to take action) or issues direction (written or oral) that the contractor considers to exceed the above limitations.

(d) The Technical Liaison assigned for this contract is: (The Technical Liaison will be added at the time of award)

Telephone: [xxx] Email: [xxx] U.S. Geological Survey Address and MS: [xxx]

(e) Only the Contracting Officer may designate a new Technical Liaison.

GS1101 Contract Administration Office. (JUL 2001)

This contract will be administered by the Contracting Officer as follows:

Lisa D. Williams U.S. Geological Survey Office of Acquisition and Grants Denver Acquisition Branch Denver Federal Center, Bldg. 67 Denver, CO 80225-0046 Telephone: (303) 236-9327 Email: ldwilliams@usgs.gov

GS1131 Unilateral Deobligation of Unexpended Funds. (MAY 2013)

The contractor shall submit all invoices under the award no later than 90 calendar days after the period of performance has expired, unless a request for extension has been submitted to the Contracting Officer. After 120 days has passed since the expiration of the performance period, the government reserves the right to issue a unilateral modification deobligating any unexpended funds, and to initiate closeout procedures.

GS1376 Software Licensing Agreements JUL 2001

The only individual authorized to sign software licensing agreements on behalf of the Government is the contracting officer. Any commercial software licenses signed by the Government are subordinate to the terms of the contract. This is in accordance with FAR Clause 52.232-39 - Unenforceability of Unauthorized Obligations which is incorporated by reference herein.

52.212-5 Contract Terms and Conditions Required To Implement Statutes or Executive Orders - Commercial Products and Commercial Services. (MAY 2024)

(a) The Contractor shall comply with the following Federal Acquisition Regulation (FAR) clauses, which are incorporated in this contract by reference, to implement provisions of law or Executive orders applicable to acquisitions of commercial products and commercial services:

(1) 52.203-19, Prohibition on Requiring Certain Internal Confidentiality Agreements or Statements (Jan 2017) (section 743 of Division E, Title VII, of the Consolidated and Further Continuing Appropriations Act, 2015 (Pub. L. 113-235) and its successor provisions in subsequent appropriations acts (and as extended in continuing resolutions)).

(2) 52.204-23, Prohibition on Contracting for Hardware, Software, and Services Developed or Provided by Kaspersky Lab Covered Entities (Dec 2023) (Section 1634 of Pub. L. 115-91).

(3) 52.204-25, Prohibition on Contracting for Certain Telecommunications and Video Surveillance Services or Equipment. (Nov 2021) (Section 889(a)(1)(A) of Pub. L. 115-232).

(4) 52.209-10, Prohibition on Contracting with Inverted Domestic Corporations (Nov 2015).

(5) 52.232-40, Providing Accelerated Payments to Small Business Subcontractors (Mar 2023) (31 U.S.C. 3903 and 10 U.S.C. 3801).

(6) 52.233-3, Protest After Award (Aug 1996) (31 U.S.C. 3553).

(7) 52.233-4, Applicable Law for Breach of Contract Claim (Oct 2004) (Public Laws 108-77 and 108-78 (19 U.S.C. 3805 note)).

mailto:ldwilliams@usgs.gov

(b) The Contractor shall comply with the FAR clauses in this paragraph (b) that the Contracting Officer has indicated as being incorporated in this contract by reference to implement provisions of law or Executive orders applicable to acquisitions of commercial products and commercial services:

[Contracting Officer check as appropriate.]

☒ (1) 52.203-6, Restrictions on Subcontractor Sales to the Government (Jun 2020), with Alternate I (Nov 2021) (41 U.S.C. 4704 and 10 U.S.C. 4655).

☐ (2) 52.203-13, Contractor Code of Business Ethics and Conduct (Nov 2021) (41 U.S.C. 3509)).

☐ (3) 52.203-15, Whistleblower Protections under the American Recovery and Reinvestment Act of 2009 (Jun 2010) (Section 1553 of Pub. L. 111-5). (Applies to contracts funded by the American Recovery and Reinvestment Act of 2009.)

☒ (4) 52.203-17, Contractor Employee Whistleblower Rights (Nov 2023) (41 U.S.C. 4712); this clause does not apply to contracts of DoD, NASA, the Coast Guard, or applicable elements of the intelligence community— see FAR 3.900(a).

☒ (5) 52.204-10, Reporting Executive Compensation and First-Tier Subcontract Awards (Jun 2020) (Pub. L.

109-282) ( 31 U.S.C. 6101 note).

☐ (6) [Reserved].

☐ (7) 52.204-14, Service Contract Reporting Requirements (Oct 2016) (Pub. L. 111-117, section 743 of Div.

C).

☐ (8) 52.204-15, Service Contract Reporting Requirements for Indefinite-Delivery Contracts (Oct 2016) (Pub.

L. 111-117, section 743 of Div. C).

☒ (9) 52.204-27, Prohibition on a ByteDance Covered Application (Jun 2023) (Section 102 of Division R of Pub. L. 117-328).

☐ (10) 52.204-28, Federal Acquisition Supply Chain Security Act Orders—Federal Supply Schedules, Governmentwide Acquisition Contracts, and Multi-Agency Contracts. (Dec 2023) (Pub. L. 115–390, title II).

☒ (11) (i) 52.204-30, Federal Acquisition Supply Chain Security Act Orders—Prohibition. (Dec 2023) (Pub. L.

115–390, title II).

☐ (ii) Alternate I (Dec 2023) of 52.204-30.

☒ (12) 52.209-6, Protecting the Government’s Interest When Subcontracting with Contractors Debarred, Suspended, or Proposed for Debarment. (Nov 2021) (31 U.S.C. 6101 note).

☐ (13) 52.209-9, Updates of Publicly Available Information Regarding Responsibility Matters (Oct 2018) (41 U.S.C. 2313).

☐ (14) [Reserved].

☐ (15) 52.219-3, Notice of HUBZone Set-Aside or Sole-Source Award (Oct 2022) (15 U.S.C. 657a).

☐ (16) 52.219-4, Notice of Price Evaluation Preference for HUBZone Small Business Concerns (Oct 2022) (if the offeror elects to waive the preference, it shall so indicate in its offer) (15 U.S.C. 657a).

☐ (17) [Reserved]

☒ (18) (i) 52.219-6, Notice of Total Small Business Set-Aside (Nov 2020) (15 U.S.C. 644).

☐ (ii) Alternate I (Mar 2020) of 52.219-6.

☐ (19) (i) 52.219-7, Notice of Partial Small Business Set-Aside (Nov 2020) (15 U.S.C. 644).

☐ (ii) Alternate I (Mar 2020) of 52.219-7.

☒ (20) 52.219-8, Utilization of Small Business Concerns (Feb 2024) (15 U.S.C. 637(d)(2) and (3)).

☐ (21) (i) 52.219-9, Small Business Subcontracting Plan (Sep 2023) (15 U.S.C. 637(d)(4)).

☐ (ii) Alternate I (Nov 2016) of 52.219-9.

☐ (iii) Alternate II (Nov 2016) of 52.219-9.

☐ (iv) Alternate III (Jun 2020) of 52.219-9.

☐ (v) Alternate IV (Sep 2023) of 52.219-9.

☐ (22) (i) 52.219-13, Notice of Set-Aside of Orders (Mar 2020) (15 U.S.C. 644(r)).

☐ (ii) Alternate I (Mar 2020) of 52.219-13.

☒ (23) 52.219-14, Limitations on Subcontracting (Oct 2022) (15 U.S.C. 637s).

☐ (24) 52.219-16, Liquidated Damages—Subcontracting…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .