Solicitation_75F40124Q00476_CDRH-2024-123208_FINAL.pdf

PDF 708 KB Posted

Attached to
Motion Capture System Federal contract opportunity
Solicitation number
75F40124Q00476
Issued by
Department of Health and Human Services Food and Drug Administration Office of Acquisition and Grant Services

About this file

This document is a combined synopsis/solicitation for a Request for Quotation (RFQ) issued by the Food and Drug Administration (FDA) for a motion capture system. The objective is to acquire equipment that enables FDA scientists to address regulatory science research questions related to the interaction of humans with diagnostic, therapeutic, and assistive medical devices.

The solicitation is for a motion capture system with specific requirements, including a minimum of six optical cameras with certain capabilities, system control box integration, and a compatible workstation. The contract will include delivery, installation, training, and a one-year manufacturer's warranty. Quotes are due by August 26, 2024, at 12:00 PM ET. The procurement will be awarded as a firm-fixed-price purchase order to the responsible quoter whose quote is the Lowest Priced Technically Acceptable. The North American Industry Classification System (NAICS) code is 334510 - Electromedical and Electrotherapeutic Apparatus Manufacturing, with a business size standard of 1250 employees.

View the file

Other files for this federal contract opportunity

Other files attached to Motion Capture System, newest first.
File Type Posted
Amendment A01 Solicitation_75F40124Q00476_CDRH-2024-123208_CO approved.pdf PDF
SF 30_Amendment A01_75F40124Q00476_CDRH-2024-123208.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

75F40124Q00476

This is a combined synopsis/solicitation for commercial products and commercial services prepared in accordance with the format in Federal Acquisition Regulation (FAR) 12.6 and (FAR)

13 as supplemented with additional information included in this notice. The incorporated provisions and clauses are those in effect through Federal Acquisition Circular (FAC) 2024-05.

THIS ANNOUNCEMENT CONSTITUTES THE ONLY SOLICITATION AND A SEPARATE

SOLICITATION WILL NOT BE ISSUED. The solicitation number for this acquisition is

75F40124Q00476 for FDA Project CDRH-2024-123208/CDRH-OSEL-24-C-1413. This combined solicitation is being issued as a Request for Quotation (RFQ). The NAICS for this solicitation is 334510 – Electromedical and Electrotherapeutic Apparatus Manufacturing. The business size standard is 1250. This requirement is being solicited as unrestricted - full and open competition. Prospective quoters are responsible for downloading the solicitation and any amendments from SAM.gov. The Government reserves the right to award the resultant firm fixed price purchase order without discussions if the Contracting Officer determines that the initial offer provides the Best Value to the Government and discussions are not necessary.

The objective is to acquire equipment that enables FDA scientists to address regulatory science research questions related to the interaction of humans with diagnostic, therapeutic, and assistive medical devices

1. Question Deadline: Questions related to this procurement shall be submitted directly by email to Contract Specialist (CS) Iris Johnson at: Iris.Johnson1@fda.hhs.gov. No phone calls will be accepted. Questions not received by the question submission deadline of:

Monday, August 20, 2024, at 12:00 p.m. Eastern Time (ET) will not be considered.

2. Quotation Deadline: The deadline for receipt of quotations for this requirement is

Friday, August 26, 2024, at 12:00 ET. Quotation submissions shall be submitted electronically to the Contract Specialist.

3. Quotation Submission Instructions:

a) The Contractor shall submit a firm-fixed price quote, including details of all cost to support the price for the required deliverables.

b) The Contractor shall include and complete the pricing table below to be considered responsive. Pricing shall include all applicable fees; any charges presented after award shall not be considered/accepted.

mailto:Iris.Johnson1@fda.hhs.gov

Line

Item

Description Quantity Unit Price

Extended Price

1 Motion Capture System

(including kits, peripherals, software, workstation etc.)

+ 12-month manufacturer’s warranty

EA $ $

2 Shipping LS $ $

3 Installation LS $ $

4 2 Days Onsite Training (Four

(4) persons)

LS $ $

Total $ $

Note: The Contractor shall complete the pricing table above to be considered responsive.

All Contract Line Items are firm-fixed price.

** Partial billing is allowed for payment for completed tasks**

c) Quotes shall be in two volumes: Volume I shall be Technical and Volume II shall be

Price. The volumes shall be separate and complete, so the evaluation of one may be accomplished independently of, and concurrently with, the evaluation of the other. No pricing information shall be provided in Volume I.

Volume I: Technical Volume shall provide the technical specifications for the product proposed and a clear table which shows where the proposed item meets or exceeds the salient characteristics. It shall address the qualification of the technicians responsible for the installation and training of the equipment. *Domestic end product is preferred and sought, where available. The country of origin for all manufactured items must be disclosed in FAR 52.212-3(f) as applicable.**

d) Quotes shall clearly reference on company letterhead the solicitation, quotation number, date of quotation, company quoting, Unique Entity Identifier (UEI), and point of contact.

f) Volume II: Price shall include a quote for all requested deliverables, with applicable discounts. Partial quotes will not be accepted.

g) Quotes shall be valid for at least sixty (60) days after close of solicitation.

h) The solicitation does not commit the Government to pay any cost for the preparation and submission of a quote. It is also advised that the Contracting Officer (CO) is the only individual who can legally commit and obligate the Government to the expenditure of public funds in connection with the proposed acquisition.

4. Award Criteria:

Quotations that do not respond to all requirements in the solicitation may be considered non-responsive without further evaluation, deliberation, or discussion. The Government reserves the right to award without discussions. The Government contemplates award of a Firm-Fixed-Price Purchase Order resulting from this solicitation to the responsible quoter whose quote confirming to the solicitation will be most advantageous to the

Government and whose quote is the Lowest Priced Technically Acceptable (LPTA).

FAR 52.212-2 Evaluation – Commercial and Commercial Services (Nov 2021)

Lowest Price, Technically Acceptable (LPTA)

(End of Provision)

STATEMENT OF WORK

Motion Capture System

CDRH-2024-123208

I. Background

The Food and Drug Administration (FDA) is responsible for protecting the public health by assuring the safety, efficacy, and security of human and veterinary drugs, biological products, medical devices, our nation’s food supply, cosmetics, and products that emit radiation. The

FDA is also responsible for advancing the public health by helping to speed innovations that make medicines and foods more effective, safer, and more affordable, and helping the public get the accurate, science-based information they need to use medicines and foods to improve their health.

The mission of the Center for Devices and Radiological Health (CDRH) is to protect and promote the public health. CDRH assures that patients and providers have timely and continued access to safe, effective, and high-quality medical devices and safe radiation-emitting products. CDRH provides consumers, patients, their caregivers, and providers with understandable and accessible science-based information about the products we oversee.

CDRH facilitates medical device innovation by advancing regulatory science, providing industry with predictable, consistent, transparent, and efficient regulatory pathways, and assuring consumer confidence in devices marketed in the U.S.

The Office of Science and Engineering Laboratories (OSEL) supports CDRH’s mission of protecting and promoting public health. OSEL undertakes the highest quality science to provide their customers with the best methods, tools and expertise to:

• Ensure readiness for emerging and innovative medical technologies

• Develop appropriate evaluation strategies and testing standards

• Create accessible and understandable public health information and,

• Deliver timely and accurate decisions for products across their life cycle.

Under OSEL, the Division of Biomedical Physics (DBP) The Division of Biomedical

Physics (DBP) participates in the Center's mission of protecting and promoting public health by identifying and investigating the biophysical interactions between medical devices and the human body. The division accomplishes this through activities supporting the OSEL mission.

DBP investigates gender-based differences in cardiac resynchronization therapy for pacemakers, development of phantoms (physical models) to assess the measurement of eye disease by optical imaging systems, evaluation and improvement of electrode reliability in neural prosthetics used to control artificial limbs, and computational modeling of active and passive implants to determine if unsafe levels of heating arise during a patient’s exposure to magnetic resonance imaging (MRI) systems. These serve the Center’s mission of advancing regulatory science, facilitating consistent and efficient regulatory pathways, and assuring continued access to safe, effective, and high-quality medical devices.

Specifically, DBP focuses on device issues that involve:

• Biomedical and tissue optics

• Biophysics and electrophysiology

• Electrical engineering

• Functional device performance and human factors, and

• Wireless communication and electromagnetic interference and compatibility

In collaboration with the Human-Device Interaction lab within the OSEL, the DBP seeks to order a motion capture system. The Human-Device Interaction lab within OSEL addresses regulatory science research questions related to diagnostic, therapeutic, and assistive medical devices. Understanding human interaction with these medical devices requires biomechanics equipment that quantifies human movement. Motion analysis (e.g. inertial measurement unit

– IMUs) is a common method by which human movement can be quantified and is becoming increasingly popular due to the portability of the technology (specifically the ability to capture movement outside of a lab).

II. Purpose/Scope

The overall objective is to acquire equipment that enables FDA scientists to address regulatory science research questions related to the interaction of humans with diagnostic, therapeutic, and assistive medical devices.

For this acquisition, a motion capture system is needed to collect more robust, high-quality signals of a subject’s movement. The goal is for the system to provide accurate quantifications of subject’s movement through three-dimensional tracking of retroreflective markers that can then be used to derive joint kinetics and kinematics.

III. System Requirements

The motion capture system shall have the following salient characteristics:

• The components and/or equipment shall be a newly manufactured, not used and refurbished, or previously used for demonstration.

• A minimum of six (6) optical cameras with the following features:

a) At least 1.3 megapixel resolution.

b) Captures data up to 250 frames per second (fps).

c) Incorporates a 6-12 millimeter vari-focal lens.

d) Camera latency less than 3.5 milliseconds.

e) Ability to update firmware.

f) Utilizes an infrared strobe.

g) Minimum field-of-view (FOV) in wide lens of 55.2 x 439 degrees and in tele lens of 27.2 x 21.8 degrees.

h) Weight of each camera is less than 600 grams.

• A minimum of six (6) 30-meter-long cables connecting the optical cameras to the main system control box (the number of cables to match the number of cameras).

• System control box capable of connecting, integrating, and synchronizing with 3rd party devices including AMTI AccuGait-Optimized force plates (Item #: ACG-O-NF) and Delsys Trigno Avanti EMG/IMU system (Stock Keeping Unit (SKU): DS-T03-

A16014).

• System control box capable of integrating digital signal from 3rd party devices, such as force plates and electromyography systems, into Vicon Nexus 2.x software.

• Workstation with the following characteristics that enable data capture from the motion capture system:

a) Microsoft Windows 10 operating system (OS), 64-bit (installed on OS hard drive).

b) GeForce RTX 3060, 12 gigabyte graphics card or better.

c) At least 1 terabyte (TB) Solid State Drive (SSD) OS hard drive.

d) Include at least a 4 TB Hard Drive Disk-Serial Advanced Technology Attachment

(HDD-SATA) data hard drive.

IV. System Delivery and Onsite Work Requirements

The vendor shall provide the following to the address below:

1. System crating, shipping (FOB Destination), and delivery.

2. System uncrating, set-up, and site cleanup.

3. Full system software and peripheral installation.

4. System test runs in accordance with manufacturer’s specifications.

5. Instruction, Operation, and Maintenance Manuals.

6. On-site hardware and software training for up to four (4) attendees.

All deliveries shall be coordinated with the Shipping Destination Technical Point of Contact

(TPOC) at least three (3) calendar days ahead of shipment. All deliveries shall be made during normal FDA White Oak Campus delivery hours: 8:00AM to 3:30PM. Onsite work shall be scheduled with the TPOC at least ten (10) working days prior to Contractor’s arrival.

V. Warranty and Technical Support

• The entire system shall be warrantied for parts and labor for a minimum of one (1) calendar year commencing from the date of installation acceptance. The warranty shall include unlimited telephone/e-mail support for questions regarding operation.

• Contractor shall provide a service report for any onsite warranty repair services.

VI. Deliverables

VII. Training

Training for four (4) personnel.

VIII. Shipping Destination/Place of Performance

SHIP TO and PERFORM AT:

U.S. Food and Drug Administration

FDA/CDRH/OSEL/DBP

Attention: TBD

10903 New Hampshire Avenue

Building 62-1105

Silver Spring, MD 20093

At a minimum, all deliverables shall be marked with the contract number and contractor’s name.

IX. Period of Performance

Work is to commence after purchase order award and to be completed upon delivery, installation and training of the equipment plus the 12-month of manufacturer’s warranty.

X. Inspection and Acceptance

The COR has the authority to accept or reject deliverables. The acceptance of deliverables and satisfactory work performance required herein shall be based upon the timeliness, accuracy, test results and suitability of the deliverable.

XI. Information Technology Purchasing Requirements

Before the Purchase order is awarded, FDA is required to get pre-approval of all the IT hardware and/or software-firmware-freeware from the FDA Chief Information Officer (CIO).

For IT hardware, this includes any device that processes or stores data, or is controlled by data (computers/data switches, etc.), but does not include passive hardware (rack, network cables, power supplies/cords, etc.). This will require the applicable Contractor to provide a

Deliverable Quantity Delivery Date

Motion Capture System including delivery, installation, test reports, training, and manuals 1 Within 60 calendar days after award

Warranty 1 One calendar year after date of acceptance complete list of hardware and/or software-firmware-freeware that the Vendor will use in fulfilling this purchase order.

This list will need to include:

1. IT hardware: manufacturer, nomenclature and model number.

2. Software (all types): manufacturer, nomenclature and version number.

Item(s) rejected by the CIO will need to be changed and the replacement item(s) would need to go through the same approval process.

Deliverables will conform to 36 CFR Part 1194.41, "Information, Documentation and

Support," and 36 CFR Part 1194.24 "Video and Multimedia Products" which are of particular importance with regard to all written, graphical or broadcast, video materials or products produced for HHS (to include training). 36 CFR Part 1194.41 outlines the requirements supporting services for products accommodating the communication needs of end-users with disabilities. The deliverables will be provided in Microsoft Word and Adobe PDF formats and compatible with versions currently used at FDA. C.A. Section 508. This language is applicable to Statements of Work (SOW) or Performance Work Statements (PWS) generated by the Department of Health and Human Services (HHS) that require a contractor or consultant to (1) produce content in any format that could be placed on a Department-owned or Department-funded Web site; or (2) write, create or produce any communications materials intended for public or internal use; to include reports, documents, charts, posters, presentations (such as Microsoft PowerPoint) or video material that could be placed on a

Department-owned or Department-funded Web site.

XII. Government Holidays

The Government is not permitted to provide on-site services on the following days that are

Federal Holidays or on other day designated as a Federal Holiday for the Washington, DC area:

(1) New Year's Day

(2) Martin Luther King's Birthday

(3) President’s Day

(4) Memorial Day

(5) Juneteenth Day

(6) Independence Day

(7) Labor Day

(8) Columbus Day

(9) Veterans' Day

(10) Thanksgiving Day

(11) Christmas Day

XIII. Points of Contact

Technical Point of Contact:

Name: TBD

Email: TBD

Phone: TBD

Contract Specialist:

Iris Johnson

Email: Iris.Johnson1@fda.hhs.gov

Phone: (301) 796-3353

Contracting Officer:

Sheneil Green

Email: Sheneil.Green@Fda.hhs.gov

Phone: (240) 402-9672

XIV. Security and Privacy

Baseline Security Requirements:

a. Applicability. The requirements herein apply whether the entire contract or modification

(hereafter "contract"), or portion thereof, includes either or both of the following:

i. Access (Physical or Logical) to Government Information: A Contractor (and/or any subcontractor) will have or will be given the ability to have, routine physical (entry) or logical (electronic) access to government information.

ii. Operate a Federal System Containing Information: A Contractor (and/or any subcontractor) will operate a federal system and information technology containing data that supports the FDA mission. In addition to the Federal Acquisition Regulation (FAR)

Subpart 2.1 definition of "information technology" (IT), the term as used in this section includes computers, ancillary equipment (including imaging peripherals, input, output, and storage devices necessary for security and surveillance), peripheral equipment designed to be controlled by the central processing unit of a computer, software, firmware and similar procedures, services (including support services), and related resources.

b. Safeguarding Information and Information Systems. All government information and information systems shall be protected in accordance with FDA policies and level of risk. At a minimum, the Contractor (and/or any subcontractor) shall:

i. Protect the:

mailto:Iris.Johnson1@fda.hhs.gov mailto:Sheneil.Green@Fda.hhs.gov

• Confidentiality, which means preserving authorized restrictions on access and disclosure, based on the security terms found in this contract, including means for protecting personal privacy and proprietary information;

• Integrity, which means guarding against improper information modification or destruction, and ensuring information non-repudiation and authenticity; and

• Availability, which means ensuring timely and reliable access to and use of information. Note to the Requiring Activity Representative: Complete the following section using the information obtained from the Information Security and Privacy Certification Checklist.

ii. Categorize all information owned and/or collected/managed on behalf of FDA and information systems that store, process, and/or transmit FDA information in accordance with FIPS 199 and National Institute of Standards and Technology (NIST) Special

Publication (SP) 800-60, Volume II: Appendices to Guide for Mapping Types of

Information and Information Systems to Security Categories. Based on information provided by the System/Data Owner, ISSO, privacy representative, or other POC, the impact level for each Security Objective (Confidentiality, Integrity, and Availability) and the Overall Impact Level, which is the highest watermark of the three factors of the information or information system are the following:

• Confidentiality: [X ] Low [ ] Moderate [ ] High

• Integrity: [ ] Low [X ] Moderate [ ] High

• Availability: [X ] Low [ ] Moderate [ ] High

• Overall Information/System Categorization:

Confidentiality

(Low, Moderate, High)

Integrity (Low, Moderate, High)

Availability (Low, Moderate, High)

Security Objectives

Impact Level:(NIST SP

800-60)

Low Mod Low

Security Objectives

Impact Level: (If

System/Information

Owner needed to downgrade/upgrade risk)

Low Low Low

Overall Impact Level:

(Low, Moderate, High) Low Low Low

Justification for downgrading/upgrading impact level:

There is no FDA data applicable to and no badge requirements for this procurement. The camera system comes

iii. Based on the agreed-upon level of impact, implement the necessary safeguards to protect all information systems and information collected and/or managed on behalf of

FDA regardless of location or purpose.

iv. Report any discovered or unanticipated threats or hazards by either the agency or contractor, or if existing safeguards have ceased to function immediately after discovery, within one (1) hour or less, to the government representative(s). This includes notifying the FDA Cybersecurity and Infrastructure Operations Coordination Center (CIOCC) within one (1) hour of discovery/detection in the event of a cybersecurity or privacy incident.

v. Adopt and implement all applicable policies, procedures, controls, and standards required by the FDA Information Security Program to ensure the confidentiality, integrity, and availability of government information and government information systems for which the Contractor is responsible under this contract or to which the

Contractor may otherwise have access under this contract. Obtain the FDA Information

Security Program security requirements, outlined in the FDA Information Security and

Privacy Protection (IS2P) policy, by contacting the CO/COR or emailing your ISSO.

c. Privacy Act. Comply with the Privacy Act requirements (when applicable), and tailor

FAR and HHSAR clauses as needed.

d. Privacy Compliance. Comply with the E-Government Act of 2002, NIST SP 800-53, and applicable FDA privacy policies and complete all the requirements below: Note to the

Requiring Activity Representative: Complete this section using the information obtained from the Information Security and Privacy Certification Checklist. This information may be included after award in the event it is not yet available at the time of acquisition.

i. Per the Office of Management and Budget (OMB) Circular A-130, Personally

Identifiable Information (PII), is "information that can be used to distinguish or trace an individual's identity, either alone or when combined with other information that is linked or linkable to a specific individual." Examples of PII include, but are not limited to the following: Social Security number, date and place of birth, mother's maiden name, biometric records, etc.

ii. Based on information provided by the ISSO, System/Data Owner, or other security or privacy representative, it has been determined that this solicitation/contract involves: [X ]

No PII [] PII with a computer workstation and software, which is why this is applicable.

iii. The Contractor shall support the agency with conducting a Privacy Threshold

Analysis (PTA) for the information system and/or information handled under this contract to determine whether or not a full Privacy Impact Assessment (PIA) needs to be completed.

• If the results of the PTA show that a full PIA is needed, the Contractor shall support the agency with completing a PIA for the system or information after completion of the PTA and in accordance with HHS and FDA policy and OMB M-03-22, Guidance for Implementing the Privacy Provisions of the E-Government Act of 2002. The

PTA/PIA shall be completed and approved prior to active use and/or collection or processing of PII and is a prerequisite to agency issuance of an authorization to operate (ATO).

• The Contractor shall support the agency in reviewing the PIA at least every three years throughout the system development lifecycle (SDLC)/information lifecycle, or when determined by the agency that a review is required based on a major change to the system, or when new types of PII are collected that introduces new or increased privacy risks, whichever comes first.

e. Controlled Unclassified Information (CUI). Executive Order 13556 defines CUI as

"information that laws, regulations, or Government-wide policies require to have safeguarding or dissemination controls, excluding classified information." The Contractor

(and/or any subcontractor) shall comply with Executive Order 13556, Controlled

Unclassified Information, (implemented at 3 CFR, part 2002) when handling CUI. 32 C.F.R.

2002.4(aa) As implemented the term "handling" refers to "…any use of CUI, including but not limited to marking, safeguarding, transporting, disseminating, re-using, and disposing of the information." 81 Fed. Reg. 63323. The requirements below apply only to nonfederal systems that process, store, or transmit CUI, or that provide security protection for such components. All sensitive information that has been identified as CUI by a regulation or statute, handled by this solicitation/contract, shall be:

i. Marked appropriately;

ii. Disclosed to authorized personnel on a Need-To-Know basis;

iii. Protected in accordance with NIST SP 800-53, Security and Privacy Controls for

Information Systems and Organizations applicable baseline if handled by a contractor system operated on behalf of the agency, or NIST SP 800-171, Protecting Controlled Unclassified

Information in Nonfederal Information Systems and Organizations if handled by internal

Contractor system; and

iv. Returned to FDA control, destroyed when no longer needed, or held until otherwise directed. Information and/or data shall be disposed of in accordance with NIST SP 800-88, Guidelines for Media Sanitization.

f. Protection of Sensitive Information. For security purposes, information is or may be sensitive because it requires security to protect its confidentiality, integrity, and/or availability. The Contractor (and/or any subcontractor) shall protect all government information that is or may be sensitive by securing it with a solution that is validated with current FIPS 140 validation certificate from the NIST CMVP.

g. Government Furnished Equipment (GFE) for Foreign Travel. FDA personnel are prohibited from taking GFE when participating in personal, unofficial travel to foreign countries. FDA personnel are strictly prohibited from teleworking using GFE in foreign countries. FDA personnel shall also request loaner GFE from the FDA Foreign Travel

h. Confidentiality and Nondisclosure of Information. Any information provided to the contractor (and/or any subcontractor) by FDA or collected by the contractor on behalf of

FDA shall be used only for the purpose of carrying out the provisions of this contract and shall not be disclosed or made known in any manner to any persons except as may be necessary in the performance of the contract. The Contractor assumes responsibility for protection of the confidentiality of Government records and shall ensure that all work performed by its employees and subcontractors shall be under the supervision of the

Contractor. Each Contractor employee or any of its subcontractors to whom any FDA records may be made available or disclosed shall be notified in writing by the Contractor that information disclosed to such employee or subcontractor can be used only for that purpose and to the extent authorized herein. The confidentiality, integrity, and availability of such information shall be protected in accordance with HHS and FDA policies. Unauthorized disclosure of information will be subject to the HHS and FDA sanction policies and/or governed by the following laws and regulations:

i. 18 U.S.C. 641 (Criminal Code: Public Money, Property or Records);

ii. 18 U.S.C. 1905 (Criminal Code: Disclosure of Confidential Information); and

iii. 44 U.S.C. Chapter 35, Subchapter I (Paperwork Reduction Act).

i. Internet Protocol Version 6 (IPv6). All procurements using Internet Protocol shall comply with OMB Memorandum M-05-22, Transition Planning for Internet Protocol

Version 6 (IPv6).

j. Information and Communications Technology (ICT). ICT products and services from prohibited entities/sources shall not be used/acquired in compliance with Public Law 115-

232, Section 889 Parts A and B, FAR 4.21, FAR 52.204.23, FAR 52.204.24, and FAR

52.204.25. The contractor (and/or any subcontractor) shall notify the government if they identify prohibited ICT products and/or services are used during the contract performance.

k. Government Websites. All new and existing public-facing government websites shall be securely configured with Hypertext Transfer Protocol Secure (HTTPS) using the most recent version of Transport Layer Security (TLS). In addition, HTTPS shall enable HTTP Strict

Transport Security (HSTS) to instruct compliant browsers to assume HTTPS at all times to reduce the number of insecure redirects and protect against attacks that attempt to downgrade connections to plain HTTP. For internal-facing websites, HTTPS is not required, but it is highly recommended. Consult the HHS Policy for Internet and Email Security for additional information.

program for official travel to any foreign country. Please see the FDA IS2P, Appendix T

Government Furnished Equipment for Foreign Travel.

l. Contract Documentation. The Contractor shall use provided templates, policies, forms, and other agency documents to comply with contract deliverables as appropriate. Note to the

Requiring Activity Representative: See Appendix C for baseline deliverables. Do NOT include in procurement documentation.

m. Standard for Encryption. The Contractor (and/or any subcontractor) shall:

i. Comply with the HHS Standard for Encryption of Computing Devices and Information to prevent unauthorized access to government information.

ii. Encrypt all sensitive federal data and information (i.e., PII, protected health information [PHI], proprietary information, etc.) in transit (i.e., email, network connections, etc.) and at rest (i.e., servers, storage devices, mobile devices, backup media, etc.) with an encryption solution that is validated with current FIPS 140 validation certificates from the NIST CMVP.

iii. Secure all devices (i.e.: desktops, laptops, mobile devices, etc.) that store and process government information and ensure devices meet HHS and FDA-specific encryption standard requirements. Maintain a complete and current inventory of all laptop computers, desktop computers, and other mobile devices and portable media that store or process sensitive government information (including PII).

iv. Verify that the encryption solutions in use have been validated under the Cryptographic

Module Validation Program to confirm compliance with current FIPS 140 validation certificates from the NIST CMVP. The Contractor shall provide a written copy of the validation documentation to the COR.

v. Use the Key Management system on the HHS personal identification verification (PIV) card or establish and use a key recovery mechanism to ensure the ability for authorized personnel to encrypt/decrypt information and recover encryption keys http://csrc.nist.gov/publications/. Encryption keys shall be provided to the COR upon request and at the conclusion of the contract.

n. Contractor Non-Disclosure Agreement (NDA). Each Contractor (and/or any subcontractor) employee having access to non-public government information under this contract shall complete the FDA non-disclosure agreement (3398 Form)], as applicable.

Contractors (and/or subcontractors) shall submit a copy of each signed and witnessed NDA to the Contracting Officer (CO) and/or CO Representative (COR) prior to performing any work under this acquisition. Note to the Requiring Activity Representative: See Appendix D for the FDA Contractor Non-Disclosure Agreement. Do NOT include in procurement documentation.

2. Training Requirements

a. Mandatory Training for All Contractor Staff. All Contractor (and/or any subcontractor) employees assigned to work on this contract shall complete the applicable FDA information security awareness, privacy, and records management training (provided upon contract award) before performing any work under this contract. Thereafter, the employees shall complete FDA information security awareness, privacy, and records management training at least annually, during the life of this contract. All provided training shall be compliant with

HHS training policies.

b. Role-based Training. All Contractor (and/or any subcontractor) employees with significant security responsibilities (as determined by the program manager) shall complete role-based training annually commensurate with their role and responsibilities in accordance with HHS and FDA policy.

c. Training Records. The Contractor (and/or any subcontractor) shall maintain training records for all its employees working under this contract in accordance with HHS and FDA policy. A copy of the training records shall be provided to the CO and/or COR within 30 days after contract award and annually thereafter or upon request.

3. Rules of Behavior

a. The Contractor (and/or any subcontractor) shall ensure that all employees performing on the contract comply with the HHS Information Technology General Rules of Behavior, HHS

Rules of Behavior for Privileged Users, and FDA policies and standards.

b. All Contractor employees performing on the contract shall read and adhere to the Rules of

Behavior before accessing Agency data or other information, systems, and/or networks that store/process government information, initially at the beginning of the contract and at least annually thereafter, which may be done as part of annual FDA Information Security

Awareness Training. If the training is provided by the contractor, the signed ROB shall be provided as a separate deliverable to the CO and/or COR per defined timelines above.

4. Incident Response

a. The Contractor (and/or any subcontractor) shall respond to all alerts/Indicators of

Compromise (IOCs) provided by HHS Computer Security Incident Response Center

(CSIRC)/FDA CIOCC /Incident Response Team teams within 24 hours, whether the response is positive or negative. FISMA defines an incident as "an occurrence that (1) actually or imminently jeopardizes, without lawful authority, the integrity, confidentiality, or availability of information or an information system; or (2) constitutes a violation or imminent threat of violation of law, security policies, security procedures, or acceptable use policies. In accordance with OMB M-17-12, Preparing for and Responding to a Breach of

Personally Identifiable

Information (PII), an incident is "an occurrence that (1) actually or imminently jeopardizes, without lawful authority, the integrity, confidentiality, or availability of information or an information system; or (2) constitutes a violation or imminent threat of violation of law, security policies, security procedures, or acceptable use policies" and a privacy breach is "the loss of control, compromise, unauthorized disclosure, unauthorized acquisition, or any similar occurrence where (1) a person other than an authorized user accesses or potentially accesses personally identifiable information or (2) an authorized user accesses or potentially accesses personally identifiable information for an other than authorized purpose." For additional information on the HHS breach response process, please see the FDA IS2P

Appendix F: Incident Response and the HHS Policy and Plan for Preparing for and

Responding to a Breach of Personally Identifiable Information (PII)."

b. In the event of a suspected or confirmed incident or breach, the Contractor (and/or any subcontractor) shall:

i. Protect all sensitive information, including any PII created, stored, or transmitted in the performance of this contract, with encryption solution that is validated with current FIPS

140 validation certificates from the NIST CMVP.

ii. NOT notify affected individuals unless so instructed by the Contracting Officer or designated representative. If so, instructed by the Contracting Officer or representative, the Contractor shall send FDA approved notifications to affected individuals as directed by FDA’s SOP.

iii. Report all suspected and confirmed information security and privacy incidents and breaches to the FDA CIOCC, COR, CO, FDA SOP (or his or her designee), and other stakeholders, including breaches involving PII, in any medium or form, including paper, oral, or electronic, as soon as possible and without unreasonable delay, no later than one

(1) hour, and consistent with the applicable FDA and HHS policy and procedures, NIST standards and guidelines, as well as US-CERT notification guidelines. The types of information required in an incident report shall include at a minimum: company and point of contact information, contact information, impact classifications/threat vector, and the type of information compromised. In addition, the Contractor shall:

• Cooperate and exchange any information, as determined by the Agency, necessary to effectively manage or mitigate a suspected or confirmed breach;

• Not include any sensitive information in the subject or body of any reporting e-mail; and

• Encrypt sensitive information in attachments to email, media, etc.

iv. Comply with OMB M-17-12, Preparing for and Responding to a Breach of

Personally Identifiable Information, and HHS and FDA breach response policies when handling PII breaches.

v. Provide full access and cooperate on all activities as determined by the Government to ensure an effective incident response, including providing all requested images, log files, and event information to facilitate rapid resolution of sensitive information incidents. This may involve disconnecting the system processing, storing, or transmitting the sensitive information from the Internet or other networks or applying additional security controls. This may also involve physical access to contractor facilities during a breach/incident investigation on demand.

5. Position Sensitivity Designations All Contractor (and/or any subcontractor) employees shall obtain a background investigation commensurate with their position sensitivity designation that complies with Parts 1400 and 731 of Title 5, Code of Federal Regulations

(CFR). The following position sensitivity designation levels apply to this solicitation/contract

(e.g. tier 1, 2, or 4): Not Applicable to this acquisition.

6. Homeland Security Presidential Directive (HSPD)-12 The Contractor (and/or any subcontractor) and its employees shall comply with Homeland Security Presidential

Directive (HSPD)-12, Policy for a Common Identification Standard for Federal Employees and Contractors; OMB M-05-24; OMB M-19-17; FIPS 201, Personal Identity Verification

(PIV) of Federal Employees and Contractors; HHS HSPD-12 policy; and Executive Order

13467, Part 1 §1.2. Note to the Requiring Activity Representative: For additional information, see HSPD-12 policy at: https://www.dhs.gov/homeland-security-presidential-directive-12

7. Roster The Contractor (and/or any subcontractor) shall submit a roster by name, position, e-mail address, phone number and responsibility, of all staff working under this acquisition where the Contractor will develop, have the ability to access, or host and/or maintain a government information system(s). The roster shall be submitted to the COR and/or CO per the COR or CO’s direction. Any revisions to the roster as a result of staffing changes shall be submitted within a timeline as directed by the COR and/or CO. The COR will notify the

Contractor of the appropriate level of investigation required for each staff member. If the employee is filling a new position, the Contractor shall provide a position description and the

Government will determine the appropriate suitability level.

8. Contract Initiation and Expiration

a. General Security Requirements. The Contractor (and/or any subcontractor) shall comply with information security and privacy requirements, Enterprise Performance Life Cycle

(EPLC) processes, HHS Enterprise Architecture requirements to ensure information is appropriately protected from initiation to expiration of the contract. All information systems development or enhancement tasks supported by the contractor shall follow the FDA EPLC framework and methodology in accordance with the FDA EPLC Project documentation, located here:

http://sharepoint.fda.gov/orgs/DelMgmtSupport/IntakeProc/EPLCv2/SitePages/v2/EPLCHo me.aspx and in accordance with the HHS Contract Closeout Guide (2012).

b. System Documentation. Contractors (and/or any subcontractors) shall follow and adhere to HHS System Development Life Cycle requirements, at a minimum, for system development and provide system documentation at designated intervals (specifically, at the expiration of the contract) within the EPLC that require artifact review and approval.

c. Sanitization of Government Files and Information. As part of contract closeout and at expiration of the contract, the Contractor (and/or any subcontractor) shall provide all required documentation in accordance with SMGs published by FDA’s Office of Acquisitions and

Grant Services (OAGS) to the CO and/or COR to certify that, at the government's direction, all electronic and paper records are appropriately disposed of and all devices and media are sanitized in accordance with NIST SP 800-88, Guidelines for Media Sanitization.

d. Notification. The Contractor (and/or any subcontractor) shall notify the CO and/or COR and system ISSO as soon as it is known that a contract employee will stop working under this contract.

e. Contractor Responsibilities upon Physical Completion of the Contract. The contractor

(and/or any subcontractors) shall return all government information and IT resources (i.e., government information in non-government-owned systems, media, and backup systems) acquired during the term of this contract to the CO and/or COR. Additionally, the Contractor shall provide a certification that all government information has been properly sanitized and purged from Contractor-owned systems, including backup systems and media used during contract performance, in accordance with HHS and FDA policies.

f. The Contractor (and/or any subcontractor) shall perform and document the actions identified in the FDA eDepart system http://inside.fda.gov:9003/EmployeeResources/NewEmployee/eDepartDepartureSystem/defa ult.htm as soon as it is known that a contract an employee will terminate work under this contract. The Contractor (and/or any subcontractor) shall coordinate with the COR via email, copying the Contract Specialist, to ensure that the appropriate person performs and documents the actions identified in the FDA eDepart system.

9. Records Management and Retention

a. The Contractor (and/or any subcontractor) shall maintain all information in accordance with Executive Order 13556 -- Controlled Unclassified Information, National Archives and

Records Administration (NARA) records retention policies and schedules and HHS Policy for Records Management and HHS and FDA policies and shall not dispose of any records unless authorized by HHSFDA.

b. In the event that a contractor (and/or any subcontractor) accidentally disposes of or destroys a record without proper authorization, he/she shall document and report the incident in accordance with HHS and FDA policies.

10. High Value Asset (HVA) If a system is identified as HVA,24 the contractor shall comply with the FDA IS2P Appendix AB: High Value Asset (HVA) Program, the HHS Policy for the High Value Asset (HVA) Program, and the DHS HVA Control Overlay25 in addition to the above requirements.

All documentation shall be available to the CO and/or COR upon request.

508 Compliance

Section 508 of the Rehabilitation Act of 1973 (29 U.S.C. 794d) requires Federal agencies to purchase information and communication technologies (ICT) that meet specific accessibility standards. This law helps to ensure that federal employees with disabilities have access to, and use of, the information and data they need to do their jobs. Furthermore, this law ensures that members of the public with disabilities have the ability to access government information and services.

There are three regulations addressing the requirements detailed in Section 508. The Section

508 technical and functional standards are codified at 36 CFR Part 1194 and may be accessed through the Access Board’s Web site at http://www.access-board.gov. The second regulation issued to implement Section 508 is the Federal Acquisition Regulation (FAR). FAR Part 39.2 requires that agency acquisitions of information and communication technology (ICT) comply with the Access Board’s standards. The entire FAR is found at Chapter 1 of the Code of Federal Register (CFR) Title 48, located at http://www.acquisition.gov. The FAR rule implementing Section 508 can be found at http://www.section508.gov. The third applicable regulation is the HHS Acquisition Regulation (HHSAR).

Regardless of format, all Web content or communications materials produced for publication on or delivery via HHS Web sites - including text, audio or video - shall conform to applicable Section 508 standards to allow federal employees and members of the public with disabilities to access information that is comparable to information provided to persons without disabilities. All contractors (including subcontractors) or consultants responsible for preparing or posting content intended for use on an HHS-funded or HHS-managed Web site shall comply with applicable Section 508 accessibility standards, and where applicable, those set forth in the referenced policy or standards documents below. Remediation of any materials that do not comply with the applicable provisions of 36 CFR Part 1194 as set forth in the SOW, shall be the responsibility of the contractor or consultant retained to produce the

Web-suitable content or communications material.

Unless an agency exception to this requirement exists, the Contractor shall conform to applicable Section 508 standards and shall apply best practices associated with Section 508 compliance during the application design, development, and testing phases. The Contractor shall utilize FDA approved tools to verify the compliance with the Section 508 standards and ensure the delivery of the fully compliant products.

The following Section 508 standards apply to this Statement of Work (SOW):

• Shall meet WCAG 2.0 A and AA

• E101.2 Equivalent Facilitation (Appendix A, Application and Scoping

Requirements)

• E203 Access to Functionality (Appendix A, Application and Scoping

Requirements)

• E204 Functional Performance Criteria (Appendix A, Application and Scoping

Requirements)

• E205 Electronic Content (Appendix A, Application and Scoping Requirements)

• E208 Support Documentation and Services (Appendix A, Application and Scoping

Requirements)

• Chapter 6 Support Documentation and Services (Appendix C, Functional

Performance Criteria and Technical Requirements)

• 302 Functional Performance Criteria (Appendix C, Functional Performance

Criteria and Technical Requirements)

• Electronic content shall be accessible to HHS acceptance criteria. Checklist for various formats are available at https://www.hhs.gov/web/section-508/making-files-accessible/index.html, or from the Section 508 Coordinator listed at https://www.hhs.gov/web/section-508/additional-resources/section-508-contacts/index.html. Materials that are final items for delivery should be accompanied by the appropriate checklist, except upon approval of the Contracting

Officer or Representative.

https://www.hhs.gov/web/section-508/making-files-accessible/index.html https://www.hhs.gov/web/section-508/making-files-accessible/index.html https://www.hhs.gov/web/section-508/additional-resources/section-508-contacts/index.html https://www.hhs.gov/web/section-508/additional-resources/section-508-contacts/index.html

Applicable Purchase Order Clauses

I. 52.252-2 CLAUSES INCORPORATED BY REFERENCE (FEB 1998)

This contract incorporates one or more clauses by reference, with the same force and effect as if they were given in full text. Upon request, the Contracting Officer will make their full text available. Also, the full text of a clause may be accesses electronically at these addresses: www.acquisition.gov AND www.acquisition.gov/hhsar.

II. 52.212-4 CONTRACT TERMS AND CONDITIONS – COMMERCIAL

PRODUCTS AND COMMERCIAL SERVICES (NOV 2023)

III. 52.212-5 CONTRACT TERMS AND CONDITIONS REQUIRED TO

IMPLEMENT STATUTES OR EXECUTIVE ORDERS – COMMERCIAL

PRODUCTS AND COMMERCIAL SERVICES (MAY 2024)

(a) The Contractor shall comply with the following Federal Acquisition Regulation

(FAR) clauses, which are incorporated in this contract by reference, to implement provisions of law or Executive orders applicable to acquisitions of commercial products and commercial services:

(1) 52.203-19, Prohibition on Requiring Certain Internal Confidentiality Agreements or

Statements (JAN 2017) (section 743 of Division E, Title VII, of the Consolidated and Further

Continuing Appropriations Act, 2015 (Pub. L. 113-235) and its successor provisions in subsequent appropriations acts (and as extended in continuing resolutions)).

(2) 52.204-23, Prohibition on Contracting for Hardware, Software, and Services

Developed or Provided by Kaspersky Lab Covered Entities (DEC 2023) (Section 1634 of Pub. L.

115-91).

(3) 52.204-25, Prohibition on Contracting for Certain Telecommunications and Video

Surveillance Services or Equipment. (NOV 2021) (Section 889(a)(1)(A) of Pub. L. 115-232).

(4) 52.209-10, Prohibition on Contracting with Inverted Domestic Corporations (NOV

2015).

(5) 52.232-40, Providing Accelerated Payments to Small Business Subcontractors (MAR

2023) ( 31 U.S.C. 3903 and 10 U.S.C. 3801).

(6) 52.233-3, Protest After Award (AUG 1996) ( 31 U.S.C. 3553).

(7) 52.233-4, Applicable Law for Breach of Contract Claim (OCT 2004) (Public Laws

108-77 and 108-78 ( 19 U.S.C. 3805 note)).

http://www.acquisition.gov/ http://www.acquisition.gov/hhsar https://www.acquisition.gov/far/52.203-19#FAR_52_203_19 https://www.acquisition.gov/far/52.204-23#FAR_52_204_23 https://www.acquisition.gov/far/52.204-25#FAR_52_204_25 https://www.acquisition.gov/far/52.209-10#FAR_52_209_10 https://www.acquisition.gov/far/52.232-40#FAR_52_232_40 https://www.govinfo.gov/link/uscode/31/3903 https://www.govinfo.gov/link/uscode/10/3801 https://www.acquisition.gov/far/52.233-3#FAR_52_233_3 http://uscode.house.gov/browse.xhtml;jsessionid=114A3287C7B3359E597506A31FC855B3 https://www.acquisition.gov/far/52.233-4#FAR_52_233_4 http://uscode.house.gov/browse.xhtml;jsessionid=114A3287C7B3359E597506A31FC855B3

(b) The Contractor shall comply with the FAR clauses in this paragraph (b) that the Contracting Officer has indicated as being incorporated in this contract by reference to implement provisions of law or Executive orders applicable to acquisitions of commercial products and commercial services:

[Contracting Officer check as appropriate.]

__ (1)…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .