Solicitation 36C26326Q0458.pdf
PDF 692 KB Posted
- Attached to
- N063--PIV Reader Install & Repair Federal contract opportunity
- Solicitation number
- 36C26326Q0458
About this file
Solicitation Summary
This is a Solicitation/Contract/Order for Commercial Products and Commercial Services (Standard Form 1449) issued by the Department of Veterans Affairs, Network Contracting Office 23 for installation and repair of PIV Readers at Grand Island VA Medical Center in Grand Island, Nebraska. The solicitation number is 36C26326Q0458, with an offer due date of April 1, 2026 at 12:00 PM CST. This is a 100% small business set-aside with a budgeted amount of $9.5 million.
The scope of work covers PIV reader installation and repair across four buildings at the Grand Island VA campus during the performance period from April 20, 2026 to July 31, 2026. Specific requirements include installing PIV readers at three clinics in the main building, installing four new readers in Building 5 resident rooms, installing five new readers on current doors in Building 7, and replacing a faulty board in Building 17. The contractor must supply all switches, wiring, magnetic locks, programming, and emergency exit buttons. All systems must be compatible with existing VA control boxes, and the preferred PIV reader model is HID class RD 40 or equivalent. Work must be phased during weekends from 8:00 AM to 4:00 PM or after 5:00 PM on weekdays to minimize patient and staff impact. All new components require one-year parts and labor warranty. The contractor must comply with personnel security requirements, including PIV badging, and maintain site cleanliness. Payment will be made electronically through the VA Electronic Invoicing System after service completion and acceptance. Technical questions must be submitted by March 25, 2026 at 4:00 PM CST, and a mandatory site visit is scheduled for March 25, 2026 at 2:30 PM CST.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| S02 Solicitation 36C26326Q0458 Amend 1.docx | DOCX document | |
| SW SE and North clinic 1st floor PIV 2026.pdf | ||
| SW 4th floor PIV.pdf | ||
| BLDG 5 floor plan PIVs 2026.pdf | ||
| 36C26326Q0458_1.docx | DOCX document | |
| Wage Determination 2015-5771.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
PAGE 1 OF 1. REQUISITION NO.
2. CONTRACT NO. 3. AWARD/EFFECTIVE DATE 4. ORDER NO. 5. SOLICITATION NUMBER 6. SOLICITATION ISSUE DATE
a. NAME b. TELEPHONE NO. (No Collect Calls) 8. OFFER DUE DATE/LOCAL
TIME
9. ISSUED BY CODE 10. THIS ACQUISITION IS UNRESTRICTED OR SET ASIDE: % FOR:
SMALL BUSINESS
HUBZONE SMALL
BUSINESS
SERVICE-DISABLED
VETERAN-OWNED
SMALL BUSINESS
WOMEN-OWNED SMALL BUSINESS
(WOSB) ELIGIBLE UNDER THE WOMEN-OWNED
SMALL BUSINESS PROGRAM
EDWOSB
8(A)
NAICS:
SIZE STANDARD:
11. DELIVERY FOR FOB DESTINA-
TION UNLESS BLOCK IS
MARKED
SEE SCHEDULE
12. DISCOUNT TERMS
13a. THIS CONTRACT IS A
RATED ORDER UNDER
DPAS (15 CFR 700)
13b. RATING
14. METHOD OF SOLICITATION
RFQ IFB RFP
15. DELIVER TO CODE 16. ADMINISTERED BY CODE
17a. CONTRACTOR/OFFEROR CODE FACILITY CODE 18a. PAYMENT WILL BE MADE BY CODE
TELEPHONE NO. UEI: EFT:
PHONE: FAX:
17b. CHECK IF REMITTANCE IS DIFFERENT AND PUT SUCH ADDRESS IN OFFER
18b. SUBMIT INVOICES TO ADDRESS SHOWN IN BLOCK 18a UNLESS BLOCK BELOW IS CHECKED
SEE ADDENDUM
19. 20. 21. 22. 23. 24.
ITEM NO. SCHEDULE OF SUPPLIES/SERVICES QUANTITY UNIT UNIT PRICE AMOUNT
(Use Reverse and/or Attach Additional Sheets as Necessary)
25. ACCOUNTING AND APPROPRIATION DATA 26. TOTAL AWARD AMOUNT (For Govt. Use Only)
27a. SOLICITATION INCORPORATES BY REFERENCE FAR 52.212-1, 52.212-4. FAR 52.212-3 AND 52.212-5 ARE ATTACHED. ADDENDA ARE ARE NOT ATTACHED.
27b. CONTRACT/PURCHASE ORDER INCORPORATES BY REFERENCE FAR 52.212-4. FAR 52.212-5 IS ATTACHED. ADDENDA ARE ARE NOT ATTACHED
28. CONTRACTOR IS REQUIRED TO SIGN THIS DOCUMENT AND RETURN _______________ 29. AWARD OF CONTRACT: REF. ___________________________________ OFFER
COPIES TO ISSUING OFFICE. CONTRACTOR AGREES TO FURNISH AND DATED ________________________________. YOUR OFFER ON SOLICITATION
DELIVER ALL ITEMS SET FORTH OR OTHERWISE IDENTIFIED ABOVE AND ON ANY (BLOCK 5), INCLUDING ANY ADDITIONS OR CHANGES WHICH ARE
ADDITIONAL SHEETS SUBJECT TO THE TERMS AND CONDITIONS SPECIFIED SET FORTH HEREIN IS ACCEPTED AS TO ITEMS:
30a. SIGNATURE OF OFFEROR/CONTRACTOR 31a. UNITED STATES OF AMERICA (SIGNATURE OF CONTRACTING OFFICER)
30b. NAME AND TITLE OF SIGNER (TYPE OR PRINT) 30c. DATE SIGNED 31b. NAME OF CONTRACTING OFFICER (TYPE OR PRINT) 31c. DATE SIGNED
AUTHORIZED FOR LOCAL REPRODUCTION (REV. NOV 2021)
PREVIOUS EDITION IS NOT USABLE Prescribed by GSA - FAR (48 CFR) 53.212
7. FOR SOLICITATION
INFORMATION CALL:
STANDARD FORM 1449
SOLICITATION/CONTRACT/ORDER FOR COMMERCIAL PRODUCTS AND COMMERCIAL SERVICES
OFFEROR TO COMPLETE BLOCKS 12, 17, 23, 24, & 30
636-26-3-5058-0112
36C26326Q0458 03-23-2026
Evan Beachy 319-688-3629 04-01-2026
12:00PM CST
36C263
DEPARTMENT OF VETERANS AFFAIRS
NETWORK CONTRACTING OFFICE 23
2501 W. 22ND STREET
SIOUX FALLS SD 57105
X 100
X
561621
$9.5 Million
N/A
X
Grand Island VA Medical Center
2201 N Broadwell Avenue
Grand Island NE 68803
Department of Veteran Affairs
Electronic Invoicing System
Tungsten Electronic Invoicing
VA Tungsten Number is: AAA544240062
Refer to VAAR Clause 852.232-72
1-877-489-6135
See CONTINUATION Page
Installation and repair of PIV Readers at the Grand Island
VA Medical Center for a period of performance of 04/20/2026 to 07/31/2026
This procurement is a total set-aside for a Small Business.
Prospective offerors must be verified as an active registration in the System for Award Management (SAM) at www.sam.gov prior to submission of their offer.
Failure to submit any of the required information, statement or certifications may result in rejection of the quote without further consideration for award.
See CONTINUATION Page
636-3660162-5058-855100 2543 010055592
636-26-3-5058-0112
John Milroy
VA-VHA-RPOC-2023-0067
36C26326Q0397
Table of Contents
SECTION A
A.1 SF 1449 SOLICITATION/CONTRACT/ORDER FOR COMMERCIAL PRODUCTS
AND COMMERCIAL SERVICES
SECTION B - CONTINUATION OF SF 1449 BLOCKS
B.1 CONTRACT ADMINISTRATION DATA
B.2 PRICE/COST SCHEDULE
ITEM INFORMATION
B.3 Performance Work Statement
B.4 RECORDS MANAGEMENT OBLIGATIONS
SECTION C - CONTRACT CLAUSES
C.1 52.212-4 CONTRACT TERMS AND CONDITIONS—COMMERCIAL PRODUCTS
AND COMMERCIAL SERVICES (NOV 2023)
C.2 52.240-91 SECURITY PROHIBITIONS AND EXCLUSIONS (NOV 2025)
(DEVIATION)
C.3 VAAR 852.232-72 ELECTRONIC SUBMISSION OF PAYMENT REQUESTS (NOV
2018)
52.252-2 CLAUSES INCORPORATED BY REFERENCE (FEB 1998)
C.4 VAAR 852.203-70 COMMERCIAL ADVERTISING (MAY 2018)
SECTION D - CONTRACT DOCUMENTS, EXHIBITS, OR ATTACHMENTS
SECTION E - SOLICITATION PROVISIONS
E.1 52.201-1 ACQUISITION 360: VOLUNTARY SURVEY (SEP 2023)
E.2 52.212-1 INSTRUCTIONS TO OFFERORS—COMMERCIAL PRODUCTS AND
COMMERCIAL SERVICES (SEP 2023)
E.3 ADDENDUM to FAR 52.212-1 INSTRUCTIONS TO OFFERORS— COMMERCIAL
ITEMS
E.4 52.212-2 EVALUATION—COMMERCIAL PRODUCTS AND COMMERCIAL
SERVICES (NOV 2021)
E.5 52.240-90 SECURITY PROHIBITIONS AND EXCLUSIONS REPRESENTATIONS
AND CERTIFICATIONS (NOV 2025) (DEVIATION)
E.6 52.233-2 SERVICE OF PROTEST (SEP 2006)
52.252-1 SOLICITATION PROVISIONS INCORPORATED BY REFERENCE (FEB
1998)
E.7 VAAR 852.233-70 PROTEST CONTENT/ALTERNATIVE DISPUTE RESOLUTION
(OCT 2018)
E.8 VAAR 852.233-71 ALTERNATE PROTEST PROCEDURE (OCT 2018)
SECTION B - CONTINUATION OF SF 1449 BLOCKS
B.1 CONTRACT ADMINISTRATION DATA
1. Contract Administration: All contract administration matters will be handled by the following individuals:
a. CONTRACTOR:
b. GOVERNMENT: Contracting Officer 36C263
2. CONTRACTOR REMITTANCE ADDRESS: All payments by the Government to the contractor will be made in accordance with:
[X] 52.232-33, Payment by Electronic Funds Transfer—System For Award Management, or
[X] 52.232-36, Payment by Third Party
3. INVOICES: Invoices shall be submitted in arrears:
a. Quarterly []
b. Semi-Annually []
c. Other [X] After service is completed and accepted
4. GOVERNMENT INVOICE ADDRESS: All Invoices from the contractor shall be submitted electronically in accordance with VAAR Clause 852.232-72 Electronic Submission of Payment
Requests.
ACKNOWLEDGMENT OF AMENDMENTS: The offeror acknowledges receipt of amendments to the Solicitation numbered and dated as follows:
AMENDMENT NO DATE
B.2 PRICE/COST SCHEDULE
ITEM INFORMATION
ITEM
NUMBE
R
DESCRIPTION OF
SUPPLIES/SERVI
CES
QUANTI
TY
UNI
T UNIT PRICE AMOUNT
1.00 JB _______________
Installation and Repair of PIV Readers for Grand Island VA Medical Center Contract Period: Base POP Begin: 04-20-2026 POP End: 07-31-2026 PRINCIPAL NAICS CODE: 561621 - Security Systems Services (except Locksmiths) PRODUCT/SERVICE CODE: N063 - Installation of Equipment - Alarm, Signal, and Security Detection Systems
1.00 JB _______________
Labor to installation and repair of PIV Readers at Grand Island VA Medical Center Contract Period: Base POP Begin: 04-20-2026 POP End: 07-31-2026 PRINCIPAL NAICS CODE: 561621 - Security Systems Services (except Locksmiths) PRODUCT/SERVICE CODE: N063 - Installation of Equipment - Alarm, Signal, and Security Detection Systems
GRAND TOTAL _______________
B.3 Performance Work Statement
1. Project Name: PIV Reader installation and Repair
2. Place of Performance:
2.1. VA Nebraska-Western Iowa Health Care System, Grand Island VA Medical Center, 2201 N Broadwell Ave, Grand Island, NE 68803
3. Scope of work:
3.1. This will cover (4) buildings on the Grand Island VA campus.
3.2. Installation of PIV readers to the Grand Island VA’s SW, SE and North clinics on the first floor of building
3.2.1. The contractor must supply all switches, wiring, magnetic locks and programming.
3.2.2. The project will require an emergency exit button for each door with a preprogrammed release time.
3.2.3. All readers must work with the current system and be fully compatible with the VA’s current control boxes.
3.2.4. Panel boxes have been identified to have sufficient reader ports to make this addition.
3.2.5. However, it will be up to the contractor to do an on-site visit for their verification.
3.2.6. All electrical wiring will be done by the contractor.
3.2.7. Preferred PIV readers will be a HID class RD 40 or equivalent.
3.2.8. Work will be done in an active medical clinic.
3.3. Installation Building 5, Install 4 new PIV readers on the south side resident rooms. (rms 7,8,9,10).
3.3.1. Work in this area will include running any network cable or electrical work in the current door frames and using the current door hardware.
3.3.2. If additional door hardware is needed it must be included by the contractor.
3.3.3. One card per new reader must be programmed and included and provided by the contractor.
3.3.4. This system must be fully intergraded into the current PIV system for this building.
3.4. Building 7, Install 5 new PIV readers on current doors.
3.4.1. These doors currently have no PIV hardware and will need everything installed and provided by the contractor to make these doors fully PIV functional.
3.4.2. All labor materials, programming and hardware needed to complete this must be provided by the contractor.
3.4.3. A total of (5) new PIV cards programmed will be provided to the VA from the contractor.
3.5. Building 17, replace and install new board to make system functional.
3.5.1. Current board is bad.
3.5.2. Board, labor and any additional items needed to make this system operational must be included by the contractor.
3.5.3. All parts will be current and like models and will be fully compatible with the current system.
3.5.4. All systems must be tested and shown to be fully compatible with the VA’s current PIV system.
3.5.5. Contractor must coordinate with the VA police to verify the system is working correctly.
3.5.6. All new components must have a one-year parts and labor warranty in writing and submitted after completion of the installation.
4. Performance Work Period of Performance: 04/20/2026 to 07/31/2026
5. Technical Representative Contact Information
5.1. Primary Name, email, phone number: Anthony Stoppkotte, Anthony.stoppkotte@va.gov 308- 216-2379
5.2. Alternate Name, email, phone number: Mitch Doht, Mitchell.Doht@va.gov, 308-339-9120
6. Work Hours Work Hours Expected
6.1. The contractor shall limit all patient or staff impacts by phasing work during weekends from 08:00 to 16:00 or after 5pm M-F.
6.2. The VA Health Care System are open from 7:30 AM to 4:00 PM (CT) M-F except for Federal Holidays.
6.3. Federal holidays observed by Federal Government can be located at https://www.opm.gov/policy-data-oversight/pay-leave/federal-holidays/
6.4. When a holiday falls on a Sunday, the following Monday will be observed as a legal holiday.
When a holiday falls on a Saturday, the preceding Friday is observed as a legal holiday by the U.S. Government agencies. Also included, would be any other day specifically declared by the President of the United States of America to be a National Holiday..
7. General Requirements
7.1. Shall contractors work involve any of the below the stated requirement shall be met.
7.2. All work shall comply with the most recent edition of USACE EM 385-1-1, comply with 29 CFR
1926, comply with 29 CFR 1910 as incorporated by reference within 29 CFR 1926, comply with ASSP A10.34, and all applicable federal, state, and local laws, ordinances, criteria, rules and regulations. Submit matters of interpretation of standards for resolution before starting work.
Where the requirements of this specification, applicable laws, criteria, ordinances, regulations, and referenced documents vary, the most stringent requirements govern except with specific approval and acceptance.
7.3. All electrical work shall comply with VHA Directive 1028, NFPA 70 (NEC), NFPA 70B, NFPA 70E, 29 CFR Part 1910 Subpart J – General Environmental Controls, 29 CFR Part 1910 Subpart S – Electrical, and 29 CFR 1926 Subpart K.
7.4. Contractor shall maintain free and unobstructed access to facility emergency services and for fire, police and other emergency response forces in accordance with NFPA 241
8. Government Furnished Property or Space
8.1. The contractor will not be provided government furnished property. Contractor equipment shall be removed or approved on a case-by-case basis by the contracting officer representative. The government is not liable for theft or security of such equipment if approved.
8.2. The contractor will be responsible for keeping a reasonably clean (free of miscellaneous debris) working environment. Failure to do so on a continuous basis shall result in the contractor being back charged for cleaning services.
https://www.opm.gov/policy-data-oversight/pay-leave/federal-holidays/
9. Site Security
9.1. In accordance with FAR 52.204-9 and VA Directive 0735 – Personal Identity Verification of
Federal Employees and Contractors, any contract person who requires routine physical access to a Federally-controlled facility and/or routine access to a Federally-controlled information system will be required to verify their identity prior to providing services under the contract. Prior to providing services under the contract, each contract person will be asked to provide two (2) forms of identification from the Accepted Identification Documentation List to the appropriate VA representative in order to obtain a proper VA-issued identification card (PIV badge). No work onsite shall ensue without issuance of a VA PIV badge or internal escorting. Contractor is expected to build lead times for PIV issuance into schedules. The general contractor shall be onsite for any subcontractors who do not have a PIV card issued to them for the duration of the subcontractor’s work including escorting subcontractors. The prime contractor shall check in all subcontractors prior to performing work each day in the engineering office space.
B.4 RECORDS MANAGEMENT OBLIGATIONS
A. Applicability This clause applies to all Contractors whose employees create, work with, or otherwise handle Federal records, as defined in Section B, regardless of the medium in which the record exists.
B. Definitions “Federal record” as defined in 44 U.S.C. § 3301, includes all recorded information, regardless of form or characteristics, made or received by a Federal agency under Federal law or in connection with the transaction of public business and preserved or appropriate for preservation by that agency or its legitimate successor as evidence of the organization, functions, policies, decisions, procedures, operations, or other activities of the United States Government or because of the informational value of data in them.
The term Federal record:
1. Includes Department of Veteran Affairs records.
2. does not include personal materials.
3. applies to records created, received, or maintained by Contractors pursuant to their
Department of Veteran Affairs contract.
4. may include deliverables and documentation associated with deliverables.
C. Requirements
1. Contractor shall comply with all applicable records management laws and regulations, as well as National Archives and Records Administration (NARA) records policies, including but not limited to the Federal Records Act (44 U.S.C. chs. 21, 29, 31, 33), NARA regulations at 36 CFR Chapter XII Subchapter B, and those policies associated with the safeguarding of records covered by the Privacy Act of 1974 (5 U.S.C. 552a).
These policies include the preservation of all records, regardless of form or characteristics, mode of transmission, or state of completion.
2. In accordance with 36 CFR 1222.32, all data created for Government use and delivered to, or falling under the legal control of, the Government are Federal records subject to the provisions of 44 U.S.C. chapters 21, 29, 31, and 33, the Freedom of Information Act
(FOIA) (5 U.S.C. 552), as amended, and the Privacy Act of 1974 (5 U.S.C. 552a), as amended and must be managed and scheduled for disposition only as permitted by statute or regulation.
3. In accordance with 36 CFR 1222.32, Contractor shall maintain all records created for
Government use or created in the course of performing the contract and/or delivered to, or under the legal control of the Government and must be managed in accordance with
Federal law. Electronic records and associated metadata must be accompanied by sufficient technical documentation to permit understanding and use of the records and data.
4. [Agency] and its contractors are responsible for preventing the alienation or unauthorized destruction of records, including all forms of mutilation. Records may not be removed from the legal custody of Department of Veteran Affairs or destroyed except for in accordance with the provisions of the agency records schedules and with the written concurrence of the Head of the Contracting Activity. Willful and unlawful destruction, damage or alienation of Federal records is subject to the fines and penalties imposed by 18 U.S.C. 2701. In the event of any unlawful or accidental removal, defacing, alteration, or destruction of records, Contractor must report to [Agency]. The agency must report promptly to NARA in accordance with 36 CFR 1230.
5. The Contractor shall immediately notify the appropriate Contracting Officer upon discovery of any inadvertent or unauthorized disclosures of information, data, documentary materials, records or equipment. Disclosure of non-public information is limited to authorized personnel with a need-to-know as described in the [contract vehicle]. The Contractor shall ensure that the appropriate personnel, administrative, technical, and physical safeguards are established to ensure the security and confidentiality of this information, data, documentary material, records and/or equipment is properly protected. The Contractor shall not remove material from Government facilities or systems, or facilities or systems operated or maintained on the Government’s behalf, without the express written permission of the Head of the Contracting Activity.
When information, data, documentary material, records and/or equipment is no longer required, it shall be returned to Department of Veteran Affairs control or the Contractor must hold it until otherwise directed. Items returned to the Government shall be hand carried, mailed, emailed, or securely electronically transmitted to the Contracting Officer or address prescribed in the [contract vehicle]. Destruction of records is EXPRESSLY
PROHIBITED unless in accordance with Paragraph (4).
6. The Contractor is required to obtain the Contracting Officer's approval prior to engaging in any contractual relationship (sub-contractor) in support of this contract requiring the disclosure of information, documentary material and/or records generated under, or relating to, contracts. The Contractor (and any sub-contractor) is required to abide by
Government and Department of Veteran Affairs guidance for protecting sensitive, proprietary information, classified, and controlled unclassified information.
7. The Contractor shall only use Government IT equipment for purposes specifically tied to or authorized by the contract and in accordance with Department of Veteran Affairs policy.
8. The Contractor shall not create or maintain any records containing any non-public
Department of Veteran Affairs information that are not specifically tied to or authorized by the contract.
9. The Contractor shall not retain, use, sell, or disseminate copies of any deliverable that contains information covered by the Privacy Act of 1974 or that which is generally protected from public disclosure by an exemption to the Freedom of Information Act.
10. The Department of Veteran Affairs owns the rights to all data and records produced as part of this contract. All deliverables under the contract are the property of the U.S.
Government for which Department of Veteran Affairs shall have unlimited rights to use, dispose of, or disclose such data contained therein as it determines to be in the public interest. Any Contractor rights in the data or deliverables must be identified as required by FAR 52.227-11 through FAR 52.227-20.
11. Training. All Contractor employees assigned to this contract who create, work with, or otherwise handle records are required to take [Agency]-provided records management training. The Contractor is responsible for confirming training has been completed according to agency policies, including initial training and any annual or refresher training.
[Note: To the extent an agency requires contractors to complete records management training, the agency must provide the training to the contractor.] D. Flowdown of requirements to subcontractors
1. The Contractor shall incorporate the substance of this clause, its terms and requirements including this paragraph, in all subcontracts under this [contract vehicle], and require written subcontractor acknowledgment of same.
2. Violation by a subcontractor of any provision set forth in this clause will be attributed to the Contractor.
B.5 VA INFORMATION AND INFORMATION SYSTEM SECURITY/PRIVACY LANGUAGE
FOR INCLUSION INTO CONTRACTS
1.1. GENERAL. This entire section applies to all acquisitions requiring any Information Security and Privacy language. Contractors, contractor personnel, subcontractors and subcontractor personnel will be subject to the same federal laws, regulations, standards, VA directives and handbooks, as VA personnel regarding information and information system security and privacy.
1.1.1.
1.2. VA INFORMATION CUSTODIAL LANGUAGE. This entire section applies to all acquisitions requiring any Information Security and Privacy language.
1.2.1. The Government shall receive unlimited rights to data/intellectual property first produced and delivered in the performance of this contract or order (hereinafter “contract”) unless expressly stated otherwise in this contract. This includes all rights to source code and all documentation created in support thereof. The primary clause used to define Government and Contractor data rights is FAR 52.227-14 Rights in Data – General. The primary clause used to define computer software license (not data/intellectual property first produced under this contractor or order) is FAR 52.227-19, Commercial Computer
Software License.
1.2.2. Information made available to the contractor by VA for the performance or administration of this contract will be used only for the purposes specified in the service agreement, SOW, PWS, PD, and/or contract. The contractor shall not use VA information in any other manner without prior written approval from a VA Contracting
Officer (CO). The primary clause used to define Government and Contractor data rights is FAR 52.227-14 Rights in Data – General.
1.2.3. VA information will not be co-mingled with any other data on the contractor’s information systems or media storage systems. The contractor shall ensure compliance with Federal and VA requirements related to data protection, data encryption, physical data segregation, logical data segregation, classification requirements and media sanitization.
1.2.4. VA reserves the right to conduct scheduled or unscheduled audits, assessments, or investigations of contractor Information Technology (IT) resources to ensure information security is compliant with Federal and VA requirements. The contractor shall provide all necessary access to records (including electronic and documentary materials related to the contracts and subcontracts) and support (including access to contractor and subcontractor staff associated with the contract) to VA, VA's Office Inspector General
(OIG),
1.2.5. and/or Government Accountability Office (GAO) staff during periodic control assessments, audits, or investigations.
1.2.6. The contractor may only use VA information within the terms of the contract and applicable Federal law, regulations, and VA policies. If new Federal information security laws, regulations or VA policies become applicable after execution of the contract, the parties agree to negotiate contract modification and adjustment necessary to implement the new laws, regulations, and/or policies.
1.2.7. The contractor shall not make copies of VA information except as specifically authorized and necessary to perform the terms of the contract. If copies are made for restoration purposes, after the restoration is complete, the copies shall be destroyed in accordance with VA Directive 6500, VA Cybersecurity Program and VA Information Security
Knowledge Service.
1.2.8. If a Veterans Health Administration (VHA) contract is terminated for default or cause with a business associate, the related local Business Associate Agreement (BAA) shall also be terminated and actions taken in accordance with VHA Directive 1605.05, Business Associate Agreements. If there is an executed national BAA associated with the contract, VA will determine what actions are appropriate and notify the contactor.
1.2.9. The contractor shall store and transmit VA sensitive information in an encrypted form, using VA-approved encryption tools which are, at a minimum, Federal Information
Processing Standards (FIPS) 140-2, Security Requirements for Cryptographic Modules
(or its successor) validated and in conformance with VA Information Security
Knowledge Service requirements. The contractor shall transmit VA sensitive information using VA approved Transport Layer Security (TLS) configured with FIPS based cipher suites in conformance with National Institute of Standards and Technology (NIST) 800-
52, Guidelines for the Selection, Configuration and Use of Transport Layer Security
(TLS) Implementations.
1.2.10. The contractor’s firewall and web services security controls, as applicable, shall meet or exceed VA’s minimum requirements.
1.2.11. Except for uses and disclosures of VA information authorized by this contract for performance of the contract, the contractor may use and disclose VA information only in two situations: (i) in response to a qualifying order of a court of competent jurisdiction after notification to VA CO (ii) with written approval from the VA CO. The contractor shall refer all requests for, demands for production of or inquiries about, VA information and information systems to the VA CO for response.
1.2.12. Notwithstanding the provision above, the contractor shall not release VA records protected by Title 38 U.S.C. § 5705, Confidentiality of medical quality- assurance records and/or Title 38 U.S.C. § 7332, Confidentiality of certain
1.2.13. medical records pertaining to drug addiction, sickle cell anemia, alcoholism or alcohol abuse or infection with Human Immunodeficiency Virus (HIV). If the contractor is in receipt of a court order or other requests for the above- mentioned information, the contractor shall immediately refer such court order or other requests to the VA CO for response.
1.2.14. Information made available to the contractor by VA for the performance or administration of this contract or information developed by the contractor in performance or administration of the contract will be protected and secured in accordance with VA
Directive 6500 and Identity and Access Management (IAM) Security processes specified in the VA Information Security Knowledge Service.
1.2.15. Any data destruction done on behalf of VA by a contractor shall be done in accordance with National Archives and Records Administration (NARA) requirements as outlined in
VA Directive 6300, Records and Information Management, VA Handbook 6300.1, Records Management Procedures, and applicable VA Records Control Schedules.
1.2.16. The contractor shall provide its plan for destruction of all VA data in its possession according to VA Directive 6500 and NIST 800-88, Guidelines for Media Sanitization prior to termination or completion of this contract. If directed by the COR/CO, the contractor shall return all Federal Records to VA for disposition.
1.2.17. Any media, such as paper, magnetic tape, magnetic disks, solid state devices or optical discs that is used to store, process, or access VA information that cannot be destroyed shall be returned to VA.The contractor shall hold the appropriate material until otherwise directed by the Contracting Officer’s Representative (COR) or CO. Items shall be returned securely via VA-approved methods. VA sensitive information must be transmitted utilizing VA-approved encryption tools which are validated under FIPS 140-2
(or its successor) and NIST 800-52. If mailed, the contractor shall send via a trackable method (USPS, UPS, FedEx, etc.) and immediately provide the COR /CO with the tracking information. Self-certification by the contractor that the data destruction requirements above have been met shall be sent to the POC /CO within 30 business days of termination of the contract.
1.2.18. All electronic storage media (hard drives, optical disks, CDs, back-up tapes, etc.) used to store, process or access VA information will not be returned to the contractor at the end of lease, loan, or trade-in. Exceptions to this paragraph will only be granted with the written approval of the VA CO.
1.3. ACCESS TO VA INFORMATION AND VA INFORMATION SYSTEMS. This section applies when any person requires access to information made available to the contractor by VA for the performance or administration of this contract or information developed by the contractor in performance or administration of the contract.
1.3.1. A contractor/subcontractor shall request logical (technical) or physical access to VA information and VA information systems for their employees and subcontractors only to the extent necessary to perform the services specified in the solicitation or contract. This includes indirect entities, both affiliate of contractor/subcontractor and agent of contractor/subcontractor.
1.3.2. Contractors and subcontractors shall sign the VA Information Security Rules of Behavior
(ROB) before access is provided to VA information and information systems (see Section
4, Training, below). The ROB contains the minimum user compliance requirements and does not supersede any policies of VA facilities or other agency components which provide higher levels of protection to VA’s information or information systems. Users who require privileged access shall complete the VA elevated privilege access request processes before privileged access is granted.
1.3.3. All contractors and subcontractors working with VA information are subject to the same security investigative and clearance requirements as those of VA appointees or employees who have access to the same types of information. The level and process of background security investigations for contractors shall be in accordance with VA
Directive and Handbook 0710, Personnel Suitability and Security Program. The Office of
Human Resources and Administration/Operations, Security and Preparedness
(HRA/OSP) is responsible for these policies and procedures. Contract personnel who require access to classified information or information systems shall have an appropriate security clearance. Verification of a Security Clearance shall be processed through the
Special Security Officer located in HRA/OSP. Contractors shall conform to all requirements stated in the National Industrial Security Program Operating Manual
(NISPOM).
1.3.4. All contractors and subcontractors shall comply with conditions specified in VAAR
852.204-71(d); Contractor operations required to be in United States. All contractors and subcontractors working with VA information must be permanently located within a jurisdiction subject to the law of the United States or its Territories to the maximum extent feasible. If services are proposed to be performed abroad the contractor must state where all non-U.S. services are provided. The contractor shall deliver to VA a detailed plan specifically addressing communications, personnel control, data protection and potential legal issues. The plan shall be approved by the COR /CO in writing prior to access being granted.
1.3.5. The contractor shall notify the COR /CO in writing immediately (no later than 24 hours) after personnel separation or occurrence of other causes. Causes may include the following:
1.3.5.1. Contractor/subcontractor personnel no longer has a need for access to VA information or VA information systems.
1.3.5.2. Contractor/subcontractor personnel are terminated, suspended, or otherwise has their work on a VA project discontinued for any reason.
1.3.5.3. Contractor believes their own personnel or subcontractor personnel may pose a threat to their company’s working environment or to any company- owned property. This includes contractor-owned assets, buildings, confidential data, customers, employees, networks, systems, trade secrets and/or VA data.
1.3.5.4. Any previously undisclosed changes to contractor/subcontractor background history are brought to light, including but not limited to changes to background investigation or employee record.
1.3.5.5. Contractor/subcontractor personnel have their authorization to work in the United
States revoked.
1.3.5.6. Agreement by which contractor provides products and services to VA has either been fulfilled or terminated, such that VA can cut off electronic and/or physical access for contractor personnel.
1.3.6. In such cases of contract fulfillment, termination, or other causes; the contractor shall take the necessary measures to immediately revoke access to VA network, property, information, and information systems (logical and physical) by contractor/subcontractor personnel. These measures include (but are not limited to): removing and then securing
Personal Identity Verification (PIV) badges and PIV – Interoperable (PIV-I) access badges, VA-issued photo badges, credentials for VA facilities and devices, VA-issued laptops, and authentication tokens. Contractors shall notify the appropriate COR/CO immediately to initiate access removal.
1.3.7. Contractors/subcontractors who no longer require VA access will return VA- issued property to VA. This property includes (but is not limited to): documents, electronic equipment, keys, and parking passes. PIV and PIV-I access badges shall be returned to the nearest VA PIV Badge Issuance Office. Once they have had access to VA information, information systems, networks and VA property in their possessions removed, contractors shall notify the appropriate VA COR/CO.
1.4. TRAINING. This entire section applies to all acquisitions which include section 3.
1.4.1. All contractors and subcontractors requiring access to VA information and VA information systems shall successfully complete the following before being granted access to VA information and its systems:
1.4.1.1. VA Privacy and Information Security Awareness and Rules of Behavior course
(Talent Management System (TMS) #10176) initially and annually thereafter.
1.4.1.2. Sign and acknowledge (electronically through TMS #10176) understanding of and responsibilities for compliance with the Organizational Rules of Behavior, relating to access to VA information and information systems initially and annually thereafter; and
1.4.1.3. Successfully complete any additional cyber security or privacy training, as required for VA personnel with equivalent information system or information access.
1.4.2. The contractor shall provide to the COR/CO a copy of the training certificates and certification of signing the Organizational Rules of Behavior for each applicable employee within five days of the initiation of the contract and annually thereafter, as required.
1.4.3. Failure to complete the mandatory annual training is grounds for suspension or termination of all physical or electronic access privileges and removal from work on the contract until such time as the required training is complete.
1.5. SECURITY INCIDENT INVESTIGATION. This entire section applies to all acquisitions requiring any Information Security and Privacy language.
1.5.1. The contractor, subcontractor, their employees, or business associates shall immediately
(within one hour) report suspected security / privacy incidents to the VA OIT’s
Enterprise Service Desk (ESD) by calling (855) 673-4357 (TTY: 711). The ESD is OIT’s
24/7/365 single point of contact for IT-related issues. After reporting to the ESD, the contractor, subcontractor, their employees, or business associates shall, within one hour, provide the COR/CO the incident number received from the ESD.
1.5.2. To the extent known by the contractor/subcontractor, the contractor/ subcontractor's notice to VA shall identify the information involved and the circumstances surrounding the incident, including the following:
1.5.2.1. The date and time (or approximation of) the Security Incident occurred.
1.5.2.2. The names of individuals involved (when applicable).
1.5.2.3. The physical and logical (if applicable) location of the incident.
1.5.2.4. Why the Security Incident took place (i.e., catalyst for the failure).
1.5.2.5. The amount of data belonging to VA believed to have been compromised.
1.5.2.6. The remediation measures the contractor is taking to ensure no future incidents of a similar nature.
1.5.3. After the contractor has provided the initial detailed incident summary to VA, they will continue to provide written updates on any new and relevant circumstances or facts they discover. The contractor, subcontractor, and their employes shall fully cooperate with VA or third-party entity performing an independent risk analysis on behalf of VA. Failure to cooperate may be deemed a material breach and grounds for contract termination.
1.5.4. VA IT contractors shall follow VA Handbook 6500, Risk Management Framework for
VA Information Systems VA Information Security Program, and VA Information
Security Knowledge Service guidance for implementing an Incident Response Plan or integrating with an existing VA implementation.
1.5.5. In instances of theft or break-in or other criminal activity, the contractor/subcontractor must concurrently report the incident to the appropriate law enforcement entity (or entities) of jurisdiction, including the VA OIG, and the VA Office of Security and Law
Enforcement. The contractor, its employees, and its subcontractors and their employees shall cooperate with VA and any law enforcement authority responsible for the investigation and prosecution of any possible criminal law violation(s) associated with any incident. The contractor/subcontractor shall cooperate with VA in any civil litigation to recover VA information, obtain monetary or other compensation from a third party for damages arising from any incident, or obtain injunctive relief against any third party arising from, or related to, the incident.
1.5.6. The contractor shall comply with VA Handbook 6500.2, Management of Breaches
Involving Sensitive Personal Information, which establishes the breach management policies and assigns responsibilities for the oversight, management and reporting procedures associated with managing of breaches.
1.5.7. With respect to unsecured Protected Health Information (PHI), the contractor is deemed to have discovered a data breach when the contractor knew or should have known of breach of such information. When a business associate is part of VHA contract, notification to the covered entity (VHA) shall be made in accordance with the executed
BAA.
1.5.8. If the contractor or any of its agents fails to protect VA sensitive personal information or otherwise engages in conduct which results in a data breach involving any VA sensitive personal information the contractor/subcontractor processes or maintains under the contract; the contractor shall pay liquidated damages to the VA as set forth in clause
852.211-76, Liquidated Damages— Reimbursement for Data Breach Costs.
1.6. INFORMATION SYSTEM DESIGN AND DEVELOPMENT. This entire section applies to information systems, systems, major applications, minor applications, enclaves, and platform information technologies (to include the subcomponents of each) designed or developed for or on behalf of VA by any non-VA entity.
1.6.1. Information systems designed or developed on behalf of VA at non-VA facilities shall comply with all applicable Federal law, regulations, and VA policies. This includes standards for the protection of electronic Protected Health Information (PHI), outlined in
45 C.F.R. Part 164, Subpart C and information and system security categorization level designations in accordance with FIPS 199, Standards for Security Categorization of
Federal Information and Information Systems and FIPS 200, Minimum Security
Requirements for Federal Information Systems. Baseline security controls shall be implemented commensurate with the FIPS 199 system security categorization (reference
VA Handbook 6500 and VA Trusted Internet Connections (TIC) Architecture).
1.6.2. Contracted new developments require creation, testing, evaluation, and authorization in compliance with VA Assessment and Authorization (A&A) processes in VA Handbook
6500 and VA Information Security Knowledge Service to obtain an Authority to Operate
(ATO). VA Directive 6517, Risk Management Framework for Cloud Computing
Services, provides the security and privacy requirements for cloud environments.
1.6.3. VA IT contractors, subcontractors and third-party service providers shall address and/or integrate applicable VA Handbook 6500, VA Handbook 6517, Risk Management
Framework for Cloud Computing Services and Information Security Knowledge Service specifications in delivered IT systems/solutions, products and/or services. If systems/solutions, products and/or services do not directly match VA security requirements, the contractor shall work though the COR/CO to identify the VA organization responsible for governance or resolution. Contractors shall comply with
FAR 39.1, specifically the prohibitions referenced.
1.6.4. The contractor (including producers and resellers) shall comply with Office of
Management and Budget (OMB) M-22-18 and M-23-16 when using third-party software on VA information systems or otherwise affecting the VA information. This includes new software purchases and software renewals for software developed or modified by major version change after the issuance date of M- 22-18 (September 14, 2022). The term
“software” includes firmware, operating systems, applications and application services
(e.g., cloud-based software), as well as products containing software. The contractor shall provide a self- attestation that secure software development practices are utilized as outlined by Executive Order (EO)14028 and NIST Guidance. A third-party assessment provided by either a certified Federal Risk and Authorization Management Program
(FedRAMP) Third Party Assessor Organization (3PAO) or one approved by the agency will be acceptable in lieu of a software producer's self- attestation.
1.6.5. The contractor shall ensure all delivered applications, systems and information systems are compliant with Homeland Security Presidential Directive (HSPD) 12 and VA Identity and Access management (IAM) enterprise identity management requirements as set forth in OMB M-19-17, M-05-24, FIPS 201-3,
1.6.6. Personal Identity Verification (PIV) of Federal Employees and Contractors (or its successor), M-21-31 and supporting NIST guidance. This applies to Commercial Off-
The-Shelf (COTS) product(s) that the contractor did not develop, all software configurations and all customizations.
1.6.7. The contractor shall ensure all contractor delivered applications and systems provide user authentication services compliant with VA Handbook 6500, VA Information Security
Knowledge Service, IAM enterprise requirements and NIST 800-63, Digital Identity
Guidelines, for direct, assertion-based authentication and/or trust-based authentication, as determined by the design and integration patterns. Direct authentication at a minimum must include Public Key Infrastructure (PKI) based authentication supportive of PIV and/or Common Access Card (CAC), as determined by the business need and compliance with VA Information Security Knowledge Service specifications.
1.6.8. The contractor shall use VA authorized technical security baseline configurations and certify to the COR that applications are fully functional and operate correctly as intended on systems in compliance with VA baselines prior to acceptance or connection into an authorized VA computing environment. If the Defense Information Systems Agency
(DISA) has created a Security Technical Implementation Guide (STIG) for the technology, the contractor may configure to comply with that STIG. If VA determines a new or updated VA configuration baseline needs to be created, the contractor shall provide required technical support to develop the configuration settings. FAR 39.1 requires the population of operating systems and applications includes all listed on the
NIST National Checklist Program Checklist Repository.
1.6.9. The standard installation, operation, maintenance, updating and patching of software shall not alter the configuration settings from VA approved baseline configuration.
Software developed for VA must be compatible with VA enterprise installer services and install to the default “program files” directory with silently install and uninstall. The contractor shall perform testing of all updates and patching prior to implementation on
VA systems.
1.6.10. Applications designed for normal end users will run in the standard user context without elevated system administration privileges.
1.6.11. The contractor-delivered solutions shall reside on VA approved operating systems.
Exceptions to this will only be granted with the written approval of the COR/CO.
1.6.12. The contractor shall design, develop, and implement security and privacy controls in accordance with the provisions of VA security system development life cycle outlined in
NIST 800-37, Risk Management Framework for Information Systems and Organizations:
A System Life Cycle Approach for Security and Privacy, VA Directive and Handbook
6500, and VA Handbook 6517.
1.6.13. The Contractor shall comply with the Privacy Act of1974 (the Act), FAR 52.224- 2
Privacy Act, and VA rules and regulations issued under the Act in the design, development, or operation of any system of records on individuals to accomplish a VA function.
1.6.14. The contractor shall ensure the security of all procured or developed information systems, systems, major applications, minor applications, enclaves and platform information technologies, including their subcomponents (hereinafter referred to as “Information
Systems”) throughout the life of this contract and any extension, warranty, or maintenance periods. This includes security configurations, workarounds, patches, hotfixes, upgrades, replacements and any physical components which may be necessary to remediate all security vulnerabilities published or known to the contractor anywhere in the information systems (including systems, operating systems, products, hardware, software, applications and firmware). The contractor shall ensure security fixes do not negatively impact the Information Systems.
1.6.15. When the contractor is responsible for operations or maintenance of the systems, the contractor shall apply the security fixes within the timeframe specified by the associated controls on the VA Information Security Knowledge Service. When security fixes involve installing third party patches (such as Microsoft OS patches or Adobe Acrobat), the contractor shall provide written notice to the VA COR/CO that the patch has been validated as to not affecting the Systems within 10 business days.
1.7. INFORMATION SYSTEM HOSTING, OPERATION, MAINTENANCE OR USE.
1.7.1. This entire section applies to information systems, systems, major applications, minor applications, enclaves, and platform information technologies (cloud and non- cloud) hosted, operated, maintained, or used on behalf of VA at non-VA facilities.
1.7.2. The contractor shall comply with all Federal laws, regulations, and VA policies for
Information systems (cloud and non-cloud) that are hosted, operated, maintained, or used on behalf of VA at non-VA facilities. Security controls for collecting, processing, transmitting, and storing of VA sensitive information, must be in place. The controls will be tested by VA or a VA sanctioned 3PAO and approved by VA prior to hosting, operation, maintenance or use of the information system or systems by or on behalf of
VA. This includes conducting compliance risk assessments, security architecture analysis, routine vulnerability scanning, system patching, change management procedures and the completion of an acceptable contingency plan for each system. The contractor’s security control procedures shall be the same as procedures used to secure
VA-operated information systems.
1.7.3. Outsourcing (contractor facility, equipment, or staff) of systems or network operations, telecommunications services or other managed services require Assessment and
Authorization (A&A) of the contractor’s systems in accordance with VA Handbook 6500 as specified in VA Information Security Knowledge
1.7.4. Service. Major changes to the A&A package may require reviewing and updating all the documentation associated with the change. The contractor’s cloud computing systems shall comply with FedRAMP and VA Directive 6517 requirements.
1.7.5. The contractor shall return all electronic storage media (hard drives, optical disks, CDs, back-up tapes, etc.) on non-VA leased or non-VA owned IT equipment used to store, process or access VA information to VA in accordance with A&A package requirements.
This applies when the contract is terminated or completed and prior to disposal of media.
The contractor shall provide its plan for destruction of all VA data in its possession according to VA Information Security Knowledge Service requirements and NIST 800-
88. The contractor shall send a self-certification that the data destruction requirements above have been met to the COR/CO within 30 business days of termination of the contract.
1.7.6. All external internet connections to VA network involving VA information must be in accordance with VA Trusted Internet Connection (TIC) Reference Architecture and VA
Directive and Handbook 6513, Secure External Connections and reviewed and approved by VA prior to implementation. Government-owned contractor-operated systems, third party or business partner networks require a Memorandum of Understanding (MOU) and
Interconnection Security Agreements (ISA).
1.7.7. Contractor procedures shall be subject to periodic, announced, or unannounced…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .