Solicitation - W911SD25QA052.pdf

PDF 3 MB Posted

Attached to
Intent to sole source for digital access to OCLC Federal contract opportunity
Solicitation number
W911SD25QA052
Issued by
Department of the Army Materiel Command Mission and Installation Contracting Command Fort Eustis

About this file

This is a Solicitation/Contract for Commercial Products and Commercial Services (Standard Form 1449) for digital library and research services from OCLC Inc. The contract (W911SD25QA052) is a Women-Owned Small Business (WOSB) set-aside for the U.S. Military Academy Library at West Point, with a delivery date of 31 March 2026. The solicitation covers six specific digital products/services from OCLC, including Cataloging and Metadata, Tipasa Subscription, FirstSearch, CONTENTdm OCR Unit, CONTENTdm Base Subscription, and CONTENTdm Collection Size, all priced on a firm fixed-price basis.

The solicitation was issued on 21 March 2025, with proposals due on 27 March 2025 at 5:00 PM. The contract will be administered by the U.S. Army Contracting Command, West Point Directorate of Contracting, with inspection and acceptance to occur at the USMA Library, Building 758 Jefferson Library. The North American Industry Classification System (NAICS) code is 519210, with a size standard that defines the business category. The contract incorporates various federal acquisition regulations and requires compliance with standard government contracting provisions related to small business, cybersecurity, supply chain security, and other standard federal procurement requirements.

View the file

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

WOMEN-OWNED SMALL

BUSINESS (WOSB)

SOLICITATION/CONTRACT/ORDER FOR COMMERCIAL PRODUCTS AND COMMERCIAL SERVICES

1. REQUISITION NUMBER PAGE 1 OF

2. CONTRACT NUMBER 3. AWARD/EFFECTIVE

DATE

4. ORDER NUMBER 5. SOLICITATION NUMBER 6. SOLICITATION ISSUE

DATE

7. FOR SOLICITATION

INFORMATION CALL:

a. NAME b. TELEPHONE NUMBER (No collect 8. OFFER DUE DATE/

LOCAL TIME

9. ISSUED BY

13b. RATING

14. METHOD OF SOLICITATION

CODE

15. DELIVER TO 16. ADMINISTERED BY CODE

18a. PAYMENT WILL BE MADE BY CODE17a. CONTRACTOR/

OFFEROR

CODE

FACILITY

CODE

CODE

TELEPHONE NUMBER

17b. CHECK IF REMITTANCE IS DIFFERENT AND PUT SUCH ADDRESS IN

OFFER

18b. SUBMIT INVOICES TO ADDRESS SHOWN IN BLOCK 18a UNLESS BLOCK

BELOW IS CHECKED

REQUEST

FOR QUOTE

(RFQ)

INVITATION

FOR BID

(IFB)

REQUEST

FOR

PROPOSAL

(RFP)

SEE ADDENDUM

19.

ITEM NUMBER

20.

SCHEDULE OF SUPPLIES/SERVICES

21.

QUANTITY

22.

UNIT

23.

UNIT PRICE

24.

AMOUNT

(Use Reverse and/or Attach Additional Sheets as Necessary)

25. ACCOUNTING AND APPROPRIATION DATA 26. TOTAL AWARD AMOUNT (For Government Use Only)

28. CONTRACTOR IS REQUIRED TO SIGN THIS DOCUMENT AND RETURN

COPIES TO ISSUING OFFICE. CONTRACTOR AGREES TO FURNISH

AND DELIVER ALL ITEMS SET FORTH OR OTHERWISE IDENTIFIED ABOVE AND

ON ANY ADDITIONAL SHEETS SUBJECT TO THE TERMS AND CONDITIONS

SPECIFIED

29. AWARD OF CONTRACT: REFERENCE OFFER

DATED . . YOUR OFFER ON SOLICITATION

(BLOCK 5), INCLUDING ANY ADDITIONS OR CHANGES WHICH ARE

SET FORTH HEREIN, IS ACCEPTED AS TO ITEMS:

30a. SIGNATURE OF OFFEROR/CONTRACTOR

30b. NAME AND TITLE OF SIGNER (Type or print) 30c. DATE SIGNED

31a. UNITED STATES OF AMERICA (SIGNATURE OF CONTRACTING OFFICER)

31b. NAME OF CONTRACTING OFFICER (Type or print) 31c. DATE SIGNED

AUTHORIZED FOR LOCAL REPRODUCTION

PREVIOUS EDITION IS NOT USABLE

STANDARD FORM 1449 (REV. 11/2021)

Prescribed by GSA - FAR (48 CFR) 53.212

10. THIS ACQUISITION IS UNRESTRICTED OR

NORTH AMERICAN

INDUSTRY CLASSIFICATION

STANDARD (NAICS):

SIZE STANDARD:

13a. THIS CONTRACT IS A

RATED ORDER UNDER

THE DEFENSE PRIORITIES

AND ALLOCATIONS

SYSTEM - DPAS (15 CFR 700)

SET ASIDE: % FOR:

11. DELIVERY FOR FREE ON

BOARD (FOB) DESTINATION

UNLESS BLOCK IS MARKED

SEE SCHEDULE

12. DISCOUNT TERMS

ARE ARE NOT ATTACHED

ARE ARE NOT ATTACHED

27a. SOLICITATION INCORPORATES BY REFERENCE (FEDERAL ACQUISITION REGULATION) FAR 52.212-1, 52.212-4. FAR 52.212-3

AND 52.212-5 ARE ATTACHED. ADDENDA

27b. CONTRACT/PURCHASE ORDER INCORPORATES BY REFERENCE FAR 52.212-4. FAR 52.212-5 IS ATTACHED. ADDENDA

8(A)

ECONOMICALLY

DISADVANTAGED

WOMEN-OWNED SMALL

BUSINESS (EDWOSB)

SERVICE-DISABLED

VETERAN-OWNED

SMALL BUSINESS

(SDVOSB)

HUBZONE SMALL

BUSINESS

SMALL BUSINESS

NOTE: OFFEROR TO COMPLETE BLOCKS 12, 17, 23, 24, AND 30.

calls)

Solicitation/Contract Form Continuation

OCLC access

W911SD25QA052

Continuation of Supplies or Services and Prices/Costs

Additional Information/Notes

Item Supplies/Service Quantity Unit Unit Price Amount

Product Service Description:

Cataloging and Metadata

Manufacturer's Name: OCLC Inc Product Service Code: 7A21 Claimant Program Code: C9E Pricing Arrangement: Firm Fixed Price

1 Each

Product Service Description: Tipasa Subscription

Manufacturer's Name: OCLC Inc Product Service Code: 7A21 Claimant Program Code: C9E Pricing Arrangement: Firm Fixed Price

1 Each

Product Service Description:

FirstSearch

Manufacturer's Name: OCLC Inc Product Service Code: 7A21 Claimant Program Code: C9E Pricing Arrangement: Firm Fixed Price

1 Each

Product Service Description:

CONTENTdm OCR Unit

Manufacturer's Name: OCLC Inc Product Service Code: 7A21 Claimant Program Code: C9E Pricing Arrangement: Firm Fixed Price

1 Each

Product Service Description:

CONTENTdm Base Subscription

Manufacturer's Name: OCLC Inc Product Service Code: 7A21 Claimant Program Code: C9E Pricing Arrangement: Firm Fixed Price

1 Each

Product Service Description:

CONTENTdm Collection Size

Manufacturer's Name: OCLC Inc Product Service Code: 7A21 Claimant Program Code: C9E Pricing Arrangement: Firm Fixed Price

1 Each

Continuation of Description

Requirements OCLC, INC Cataloging and Metadata: Tipasa Sub

North American Industry Classification System (NAICS): 519210

North American Industry Classification System (NAICS): 519210

North American Industry Classification System (NAICS): 519210

North American Industry Classification System (NAICS): 519210

North American Industry Classification System (NAICS): 519210

North American Industry Classification System (NAICS): 519210

Continuation of Inspection and Acceptance

Overall Contract Inspection/Acceptance Locations

Inspection and Acceptance Location

Both Destination Instructions: Acceptance with in 7 days

DoDAAC: W16W7U CountryCode: USA

W1FB USMA LIBRARY

BLDG 758 JEFFERSON LIBRAARY, CULLUM ROAD

WEST POINT, NY 10996-1595

UNITED STATES

Inspection and Acceptance Location

Both Destination Instructions: Acceptance with in 7 days

DoDAAC: W16W7U CountryCode: USA

W1FB USMA LIBRARY

BLDG 758 JEFFERSON LIBRAARY, CULLUM ROAD

WEST POINT, NY 10996-1595

UNITED STATES

Inspection and Acceptance Location

Both Destination Instructions: Acceptance with in 7 days

DoDAAC: W16W7U CountryCode: USA

W1FB USMA LIBRARY

BLDG 758 JEFFERSON LIBRAARY, CULLUM ROAD

WEST POINT, NY 10996-1595

UNITED STATES

Inspection and Acceptance Location

Both Destination Instructions: Acceptance with in 7 days

DoDAAC: W16W7U CountryCode: USA

W1FB USMA LIBRARY

BLDG 758 JEFFERSON LIBRAARY, CULLUM ROAD

WEST POINT, NY 10996-1595

UNITED STATES

Inspection and Acceptance Location

Both Destination Instructions: Acceptance with in 7 days

DoDAAC: W16W7U CountryCode: USA

W1FB USMA LIBRARY

BLDG 758 JEFFERSON LIBRAARY, CULLUM ROAD

WEST POINT, NY 10996-1595

UNITED STATES

Inspection and Acceptance Location

Both Destination Instructions: Acceptance with in 7 days

DoDAAC: W16W7U CountryCode: USA

W1FB USMA LIBRARY

BLDG 758 JEFFERSON LIBRAARY, CULLUM ROAD

WEST POINT, NY 10996-1595

UNITED STATES

Continuation of Deliveries or Performance

Delivery On Or Before Delivery Date 31 Mar 2026

Party to Pay Transportation Cost: Contractor

Point Type: Destination

Line Item Delivery Schedule Quantity Address and POC Special Handling/Notes

Delivery On Or Before Delivery Date 31 Mar 2026

1 Each Ship To DoDAAC: W16W7U CountryCode: USA

W1FB USMA LIBRARY

BLDG 758 JEFFERSON LIBRAARY,

CULLUM ROAD

WEST POINT, NY 10996-1595

UNITED STATES

FoB Details

Party to Pay Transportation Cost:

Contractor

Point Type: Destination

Delivery On Or Before Delivery Date 31 Mar 2026

1 Each Ship To DoDAAC: W16W7U CountryCode: USA

W1FB USMA LIBRARY

BLDG 758 JEFFERSON LIBRAARY,

CULLUM ROAD

WEST POINT, NY 10996-1595

UNITED STATES

FoB Details

Party to Pay Transportation Cost:

Contractor

Point Type: Destination

Delivery On Or Before Delivery Date 31 Mar 2026

1 Each Ship To DoDAAC: W16W7U CountryCode: USA

W1FB USMA LIBRARY

BLDG 758 JEFFERSON LIBRAARY,

CULLUM ROAD

WEST POINT, NY 10996-1595

UNITED STATES

FoB Details

Party to Pay Transportation Cost:

Contractor

Point Type: Destination

Delivery On Or Before Delivery Date 31 Mar 2026

1 Each Ship To DoDAAC: W16W7U CountryCode: USA

W1FB USMA LIBRARY

BLDG 758 JEFFERSON LIBRAARY,

CULLUM ROAD

WEST POINT, NY 10996-1595

UNITED STATES

FoB Details

Party to Pay Transportation Cost:

Contractor

Point Type: Destination

Delivery On Or Before

1 Each Ship To DoDAAC: W16W7U FoB Details

Delivery Date 31 Mar 2026

CountryCode: USA

W1FB USMA LIBRARY

BLDG 758 JEFFERSON LIBRAARY,

CULLUM ROAD

WEST POINT, NY 10996-1595

UNITED STATES

Party to Pay Transportation Cost:

Contractor

Point Type: Destination

Delivery On Or Before Delivery Date 31 Mar 2026

1 Each Ship To DoDAAC: W16W7U CountryCode: USA

W1FB USMA LIBRARY

BLDG 758 JEFFERSON LIBRAARY,

CULLUM ROAD

WEST POINT, NY 10996-1595

UNITED STATES

FoB Details

Party to Pay Transportation Cost:

Contractor

Point Type: Destination

Contract Clauses

FAR Clauses Incorporated by Reference

Number Title Effective Date

Alternate/ Deviation

Variation Effective Date

52.204-13 System for Award Management Maintenance. Oct 2018 52.204-18 Commercial and Government Entity Code Maintenance. Aug 2020 52.212-4 Contract Terms and Conditions-Commercial Products and Commercial Services. Nov 2023 52.233-3 Protest after Award. Aug 1996 52.232-33 Payment by Electronic Funds Transfer-System for Award Management. Oct 2018

DFARS Clauses Incorporated by Reference

Number Title Effective Date

Alternate/ Deviation

Variation Effective Date

252.244-7000 Subcontracts for Commercial Products or Commercial Services. Nov 2023 252.247-7023 Transportation of Supplies by Sea. Oct 2024 252.203-7002 Requirement to Inform Employees of Whistleblower Rights. Dec 2022 252.225-7001 Buy American and Balance of Payments Program. Feb 2024 252.225-7056 Prohibition Regarding Business Operations with the Maduro Regime. Jan 2023 252.225-7060 Prohibition on Certain Procurements from the Xinjiang Uyghur Autonomous Region. Jun 2023 252.232-7003 Electronic Submission of Payment Requests and Receiving Reports. Dec 2018 252.232-7010 Levies on Contract Payments. Dec 2006

FAR Clauses Incorporated by Full Text

52.204-25 Prohibition on Contracting for Certain Telecommunications and Video Surveillance Services or Equipment.

(Nov 2021)

As prescribed in 4.2105(b), insert the following clause:

Prohibition on Contracting for Certain Telecommunications and Video Surveillance Services or Equipment (Nov 2021)

(a) Definitions. As used in this clause-

Backhaul means intermediate links between the core network, or backbone network, and the small subnetworks at the edge of the network (e.g., connecting cell phones/towers to the core telephone network). Backhaul can be wireless (e.g., microwave) or wired (e.g., fiber optic, coaxial cable, Ethernet).

Covered foreign country means The People's Republic of China.

Covered telecommunications equipment or services means-

(1) Telecommunications equipment produced by Huawei Technologies Company or ZTE Corporation (or any subsidiary or affiliate of such entities);

(2) For the purpose of public safety, security of Government facilities, physical security surveillance of critical infrastructure, and other national security purposes, video surveillance and telecommunications equipment produced by Hytera Communications Corporation, Hangzhou Hikvision Digital Technology Company, or Dahua Technology Company (or any subsidiary or affiliate of such entities);

(3) Telecommunications or video surveillance services provided by such entities or using such equipment; or

(4) Telecommunications or video surveillance equipment or services produced or provided by an entity that the Secretary of Defense, in consultation with the Director of National Intelligence or the Director of the Federal Bureau of Investigation, reasonably believes to be an entity owned or controlled by, or otherwise connected to, the government of a covered foreign country.

Critical technology means-

(1) Defense articles or defense services included on the United States Munitions List set forth in the International Traffic in Arms Regulations under subchapter M of chapter I of title 22, Code of Federal Regulations;

(2) Items included on the Commerce Control List set forth in Supplement No. 1 to part 774 of the Export Administration Regulations under subchapter C of chapter VII of title 15, Code of Federal Regulations, and controlled-

(i) Pursuant to multilateral regimes, including for reasons relating to national security, chemical and biological weapons proliferation, nuclear nonproliferation, or missile technology; or

(ii) For reasons relating to regional stability or surreptitious listening;

(3) Specially designed and prepared nuclear equipment, parts and components, materials, software, and technology covered by part 810 of title 10, Code of Federal Regulations (relating to assistance to foreign atomic energy activities);

(4) Nuclear facilities, equipment, and material covered by part 110 of title 10, Code of Federal Regulations (relating to export and import of nuclear equipment and material);

(5) Select agents and toxins covered by part 331 of title 7, Code of Federal Regulations, part 121 of title 9 of such Code, or part 73 of title 42 of such Code; or

(6) Emerging and foundational technologies controlled pursuant to section 1758 of the Export Control Reform Act of 2018 (50 U.S.C. 4817).

Interconnection arrangements means arrangements governing the physical connection of two or more networks to allow the use of another's network to hand off traffic where it is ultimately delivered (e.g., connection of a customer of telephone provider A to a customer of telephone company B) or sharing data and other information resources.

Reasonable inquiry means an inquiry designed to uncover any information in the entity's possession about the identity of the producer or provider of covered telecommunications equipment or services used by the entity that excludes the need to include an internal or third-party audit.

Roaming means cellular communications services (e.g., voice, video, data) received from a visited network when unable to connect to the facilities of the home network either because signal coverage is too weak or because traffic is too high.

Substantial or essential component means any component necessary for the proper function or performance of a piece of equipment, system, or service.

(b) Prohibition.

(1) Section 889(a)(1)(A) of the John S. McCain National Defense Authorization Act for Fiscal Year 2019 (Pub. L. 115-232) prohibits the head of an executive agency on or after August 13, 2019, from procuring or obtaining, or extending or renewing a contract to procure or obtain, any equipment, system, or service that uses covered telecommunications equipment or services as a substantial or essential component of any system, or as critical technology as part of any system. The Contractor is prohibited from providing to the Government any equipment, system, or service that uses covered telecommunications equipment or services as a substantial or essential component of any system, or as critical technology as part of any system, unless an exception at paragraph (c) of this clause applies or the covered telecommunication equipment or services are covered by a waiver described in FAR 4.2104.

(2) Section 889(a)(1)(B) of the John S. McCain National Defense Authorization Act for Fiscal Year 2019 (Pub. L. 115-232) prohibits the head of an executive agency on or after August 13, 2020, from entering into a contract, or extending or renewing a contract, with an entity that uses any equipment, system, or service that uses covered telecommunications equipment or services as a substantial or essential component of any system, or as critical technology as part of any system, unless an exception at paragraph (c) of this clause applies or the covered telecommunication equipment or services are covered by a waiver described in FAR 4.2104. This prohibition applies to the use of covered telecommunications equipment or services, regardless of whether that use is in performance of work under a Federal contract.

(c) Exceptions. This clause does not prohibit contractors from providing-

(1) A service that connects to the facilities of a third-party, such as backhaul, roaming, or interconnection arrangements; or

(2) Telecommunications equipment that cannot route or redirect user data traffic or permit visibility into any user data or packets that such equipment transmits or otherwise handles.

(d) Reporting requirement.

(1) In the event the Contractor identifies covered telecommunications equipment or services used as a substantial or essential component of any system, or as critical technology as part of any system, during contract performance, or the Contractor is notified of such by a subcontractor at any tier or by any other source, the Contractor shall report the information in paragraph (d)(2) of this clause to the Contracting Officer, unless elsewhere in this contract are established procedures for reporting the information; in the case of the Department of Defense, the Contractor shall report to the website at https://dibnet.dod.mil. For indefinite delivery contracts, the Contractor shall report to the Contracting Officer for the indefinite delivery contract and the Contracting Officer(s) for any affected order or, in the case of the Department of Defense, identify both the indefinite delivery contract and any affected orders in the report provided at https://dibnet.dod.mil.

(2) The Contractor shall report the following information pursuant to paragraph (d)(1) of this clause

(i) Within one business day from the date of such identification or notification: the contract number; the order number(s), if applicable; supplier name;

supplier unique entity identifier (if known); supplier Commercial and Government Entity (CAGE) code (if known); brand; model number (original equipment manufacturer number, manufacturer part number, or wholesaler number); item description; and any readily available information about mitigation actions undertaken or recommended.

(ii) Within 10 business days of submitting the information in paragraph (d)(2)(i) of this clause: any further available information about mitigation actions undertaken or recommended. In addition, the Contractor shall describe the efforts it undertook to prevent use or submission of covered telecommunications equipment or services, and any additional efforts that will be incorporated to prevent future use or submission of covered telecommunications equipment or services.

(e) Subcontracts. The Contractor shall insert the substance of this clause, including this paragraph (e) and excluding paragraph (b)(2), in all subcontracts and other contractual instruments, including subcontracts for the acquisition of commercial products or commercial services.

(End of clause)

52.203-19 Prohibition on Requiring Certain Internal Confidentiality Agreements or Statements. (Jan 2017)

As prescribed in 3.909-3(b), insert the following clause:

Prohibition on Requiring Certain Internal Confidentiality Agreements or Statements (Jan 2017)

(a) Definitions. As used in this clause-

Internal confidentiality agreement or statement means a confidentiality agreement or any other written statement that the contractor requires any of its employees or subcontractors to sign regarding nondisclosure of contractor information, except that it does not include confidentiality agreements arising out of civil litigation or confidentiality agreements that contractor employees or subcontractors sign at the behest of a Federal agency.

Subcontract means any contract as defined in subpart 2.1 entered into by a subcontractor to furnish supplies or services for performance of a prime contract or a subcontract. It includes but is not limited to purchase orders, and changes and modifications to purchase orders.

Subcontractor means any supplier, distributor, vendor, or firm (including a consultant) that furnishes supplies or services to or for a prime contractor or another subcontractor.

(b) The Contractor shall not require its employees or subcontractors to sign or comply with internal confidentiality agreements or statements prohibiting or otherwise restricting such employees or subcontractors from lawfully reporting waste, fraud, or abuse related to the performance of a Government contract to a designated investigative or law enforcement representative of a Federal department or agency authorized to receive such information (e.g., agency Office of the Inspector General).

(c) The Contractor shall notify current employees and subcontractors that prohibitions and restrictions of any preexisting internal confidentiality agreements or statements covered by this clause, to the extent that such prohibitions and restrictions are inconsistent with the prohibitions of this clause, are no longer in effect.

(d) The prohibition in paragraph (b) of this clause does not contravene requirements applicable to Standard Form 312 (Classified Information Nondisclosure Agreement), Form 4414 (Sensitive Compartmented Information Nondisclosure Agreement), or any other form issued by a Federal department or agency governing the nondisclosure of classified information.

(e) In accordance with section 743 of Division E, Title VII, of the Consolidated and Further Continuing Appropriations Act, 2015, (Pub. L. 113-235), and its successor provisions in subsequent appropriations acts (and as extended in continuing resolutions) use of funds appropriated (or otherwise made available) is prohibited, if the Government determines that the Contractor is not in compliance with the provisions of this clause.

(f) The Contractor shall include the substance of this clause, including this paragraph (f), in subcontracts under such contracts.

(End of clause)

52.233-4 Applicable Law for Breach of Contract Claim. (Oct 2004)

As prescribed in 33.215(b), insert the following clause:

Applicable Law for Breach of Contract Claim (Oct 2004)

United States law will apply to resolve any claim of breach of this contract.

(End of clause)

DFARS Clauses Incorporated by Full Text

252.203-7000 Requirements Relating to Compensation of Former DoD Officials. (Sep 2011)

As prescribed in 203.171-4(a), use the following clause:

REQUIREMENTS RELATING TO COMPENSATION OF FORMER DOD OFFICIALS (SEP 2011)

(a) Definition. "Covered DoD official," as used in this clause, means an individual that-

(1) Leaves or left DoD service on or after January 28, 2008; and

(2)(i) Participated personally and substantially in an acquisition as defined in 41 U.S.C. 131 with a value in excess of $10 million, and serves or served-

(A) In an Executive Schedule position under subchapter II of chapter 53 of Title 5, United States Code;

(B) In a position in the Senior Executive Service under subchapter VIII of chapter 53 of Title 5, United States Code; or

(C) In a general or flag officer position compensated at a rate of pay for grade O-7 or above under section 201 of Title 37, United States Code; or

(ii) Serves or served in DoD in one of the following positions: program manager, deputy program manager, procuring contracting officer, administrative contracting officer, source selection authority, member of the source selection evaluation board, or chief of a financial or technical evaluation team for a contract in an amount in excess of $10 million.

(b) The Contractor shall not knowingly provide compensation to a covered DoD official within 2 years after the official leaves DoD service, without first determining that the official has sought and received, or has not received after 30 days of seeking, a written opinion from the appropriate DoD ethics counselor regarding the applicability of post-employment restrictions to the activities that the official is expected to undertake on behalf of the Contractor.

(c) Failure by the Contractor to comply with paragraph (b) of this clause may subject the Contractor to rescission of this contract, suspension, or debarment in accordance with 41 U.S.C. 2105(c).

(End of clause)

252.204-7018 Prohibition on the Acquisition of Covered Defense Telecommunications Equipment or Services.

(Jan 2023)

As prescribed in 204.2105(c), use the following clause:

PROHIBITION ON THE ACQUISITION OF COVERED DEFENSE TELECOMMUNICATIONS EQUIPMENT OR SERVICES (JAN 2023)

(a) Definitions. As used in this clause-

"Covered defense telecommunications equipment or services" means-

(1) Telecommunications equipment produced by Huawei Technologies Company or ZTE Corporation, or any subsidiary or affiliate of such entities;

(2) Telecommunications services provided by such entities or using such equipment; or

(3) Telecommunications equipment or services produced or provided by an entity that the Secretary of Defense reasonably believes to be an entity owned or controlled by, or otherwise connected to, the government of a covered foreign country.

"Covered foreign country" means-

(1) The People's Republic of China; or

(2) The Russian Federation.

"Covered missions" means-

(1) The nuclear deterrence mission of DoD, including with respect to nuclear command, control, and communications, integrated tactical warning and attack assessment, and continuity of Government; or

(2) The homeland defense mission of DoD, including with respect to ballistic missile defense.

"Critical technology" means-

(1) Defense articles or defense services included on the United States Munitions List set forth in the International Traffic in Arms Regulations under subchapter M of chapter I of title 22, Code of Federal Regulations;

(2) Items included on the Commerce Control List set forth in Supplement No. 1 to part 774 of the Export Administration Regulations under subchapter C of chapter VII of title 15, Code of Federal Regulations, and controlled-

(i) Pursuant to multilateral regimes, including for reasons relating to national security, chemical and biological weapons proliferation, nuclear nonproliferation, or missile technology; or

(ii) For reasons relating to regional stability or surreptitious listening;

(3) Specially designed and prepared nuclear equipment, parts and components, materials, software, and technology covered by part 810 of title 10, Code of Federal Regulations (relating to assistance to foreign atomic energy activities);

(4) Nuclear facilities, equipment, and material covered by part 110 of title 10, Code of Federal Regulations (relating to export and import of nuclear equipment and material);

(5) Select agents and toxins covered by part 331 of title 7, Code of Federal Regulations, part 121 of title 9 of such Code, or part 73 of title 42 of such Code; or

(6) Emerging and foundational technologies controlled pursuant to section 1758 of the Export Control Reform Act of 2018 (50 U.S.C. 4817).

"Substantial or essential component" means any component necessary for the proper function or performance of a piece of equipment, system, or service.

(b) Prohibition. In accordance with section 1656 of the National Defense Authorization Act for Fiscal Year 2018 (Pub. L. 115-91), the contractor shall not provide to the Government any equipment, system, or service to carry out covered missions that uses covered defense telecommunications equipment or services as a substantial or essential component of any system, or as critical technology as part of any system, unless the covered defense telecommunication equipment or services are covered by a waiver described in Defense Federal Acquisition Regulation Supplement 204.2104.

(c) Procedures. The Contractor shall review the list of excluded parties in the System for Award Management (SAM) at https://www.sam.gov for entities that are excluded when providing any equipment, system, or service, to carry out covered missions, that uses covered defense telecommunications equipment or services as a substantial or essential component of any system, or as critical technology as part of any system, unless a waiver is granted.

(d) Reporting.

(1) In the event the Contractor identifies covered defense telecommunications equipment or services used as a substantial or essential component of any system, or as critical technology as part of any system, during contract performance, the Contractor shall report at https://dibnet.dod.mil the information in paragraph (d)(2) of this clause.

(2) The Contractor shall report the following information pursuant to paragraph (d)(1) of this clause:

(i) Within 3 business days from the date of such identification or notification: the contract number; the order number(s), if applicable; supplier name;

brand; model number (original equipment manufacturer number, manufacturer part number, or wholesaler number); item description; and any readily available information about mitigation actions undertaken or recommended.

(ii) Within 30 business days of submitting the information in paragraph (d)(2)(i) of this clause: any further available information about mitigation actions undertaken or recommended. In addition, the Contractor shall describe the efforts it undertook to prevent use or submission of a covered defense telecommunications equipment or services, and any additional efforts that will be incorporated to prevent future use or submission of covered telecommunications equipment or services.

(e) Subcontracts. The Contractor shall insert the substance of this clause, including this paragraph (e), in all subcontracts and other contractual instruments, including subcontracts for the acquisition of commercial products or commercial services.

(End of clause)

252.204-7012 Safeguarding Covered Defense Information and Cyber Incident Reporting. (DEVIATION 2024-O0013 REVISION 1)

(May 2024) Deviation 2024-O0013 (May 2024)

252.204-7012 Safeguarding Covered Defense Information and Cyber Incident Reporting. (DEVIATION 2024-O0013 REVISION 1)

Use the following clause in lieu of the clause at DFARS 252.204-7012.

SAFEGUARDING COVERED DEFENSE INFORMATION AND CYBER INCIDENT REPORTING (MAY 2024) (DEVIATION 2024-O0013

REVISION 1)

(a) Definitions. As used in this clause-

Adequate security means protective measures that are commensurate with the consequences and probability of loss, misuse, or unauthorized access to, or modification of information.

Compromise means disclosure of information to unauthorized persons, or a violation of the security policy of a system, in which unauthorized intentional or unintentional disclosure, modification, destruction, or loss of an object, or the copying of information to unauthorized media may have occurred.

Contractor attributional/proprietary information means information that identifies the contractor(s), whether directly or indirectly, by the grouping of information that can be traced back to the contractor(s) (e.g., program description, facility locations), personally identifiable information, as well as trade secrets, commercial or financial information, or other commercially sensitive information that is not customarily shared outside of the company.

Controlled technical information means technical information with military or space application that is subject to controls on the access, use, reproduction, modification, performance, display, release, disclosure, or dissemination. Controlled technical information would meet the criteria, if disseminated, for distribution statements B through F using the criteria set forth in DoD Instruction 5230.24, Distribution Statements on Technical Documents. The term does not include information that is lawfully publicly available without restrictions.

Covered contractor information system means an unclassified information system that is owned, or operated by or for, a contractor and that processes, stores, or transmits covered defense information.

Covered defense information means unclassified controlled technical information or other information, as described in the Controlled Unclassified Information (CUI) Registry at http://www.archives.gov/cui/registry/category-list.html, that requires safeguarding or dissemination controls pursuant to and consistent with law, regulations, and Governmentwide policies, and is-

(1) Marked or otherwise identified in the contract, task order, or delivery order and provided to the contractor by or on behalf of DoD in support of the performance of the contract; or

(2) Collected, developed, received, transmitted, used, or stored by or on behalf of the contractor in support of the performance of the contract.

Cyber incident means actions taken through the use of computer networks that result in a compromise or an actual or potentially adverse effect on an information system and/or the information residing therein.

Forensic analysis means the practice of gathering, retaining, and analyzing computer-related data for investigative purposes in a manner that maintains the integrity of the data.

Information system means a discrete set of information resources organized for the collection, processing, maintenance, use, sharing, dissemination, or disposition of information.

Malicious software means computer software or firmware intended to perform an unauthorized process that will have adverse impact on the confidentiality, integrity, or availability of an information system. This definition includes a virus, worm, Trojan horse, or other code-based entity that infects a host, as well as spyware and some forms of adware.

Media means physical devices or writing surfaces including, but is not limited to, magnetic tapes, optical disks, magnetic disks, large-scale integration memory chips, and printouts onto which covered defense information is recorded, stored, or printed within a covered contractor information system.

Operationally critical support means supplies or services designated by the Government as critical for airlift, sealift, intermodal transportation services, or logistical support that is essential to the mobilization, deployment, or sustainment of the Armed Forces in a contingency operation.

Rapidly report means within 72 hours of discovery of any cyber incident.

Technical information means technical data or computer software, as those terms are defined in the clause at DFARS 252.227-7013, Rights in Technical Data-Other Than Commercial Products and Commercial Services, regardless of whether or not the clause is incorporated in this solicitation or contract. Examples of technical information include research and engineering data, engineering drawings, and associated lists, specifications, standards, process sheets, manuals, technical reports, technical orders, catalog-item identifications, data sets, studies and analyses and related information, and computer software executable code and source code.

(b) Adequate security. The Contractor shall provide adequate security on all covered contractor information systems. To provide adequate security, the Contractor shall implement, at a minimum, the following information security protections:

(1) For covered contractor information systems that are part of an Information Technology (IT) service or system operated on behalf of the Government, the following security requirements apply:

(i) Cloud computing services shall be subject to the security requirements specified in the clause 252.239-7010, Cloud Computing Services, of this contract.

(ii) Any other such IT service or system (i.e., other than cloud computing) shall be subject to the security requirements specified elsewhere in this contract.

(2) For covered contractor information systems that are not part of an IT service or system operated on behalf of the Government and therefore are not subject to the security requirement specified at paragraph (b)(1) of this clause, the following security requirements apply:

(i) Except as provided in paragraph (b)(2)(ii) of this clause, the covered contractor information system shall be subject to the security requirements in National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171, “Protecting Controlled Unclassified Information in Nonfederal Information Systems and Organizations”, Revision 2 (available via the internet at https://nvlpubs.nist.gov/nistpubs/SpecialPublications /NIST.SP.800-171r2.pdf).

(ii)(A) The Contractor shall implement NIST SP 800-171, as soon as practical, but not later than December 31, 2017. For all contracts awarded prior to October 1, 2017, the Contractor shall notify the DoD Chief Information Officer (CIO), via email at osd.dibcsia@mail.mil, within 30 days of contract award, of any security requirements specified by NIST SP 800-171 not implemented at the time of contract award.

(B) The Contractor shall submit requests to vary from NIST SP 800-171 in writing to the Contracting Officer, for consideration by the DoD CIO. The Contractor need not implement any security requirement adjudicated by an authorized representative of the DoD CIO to be nonapplicable or to have an alternative, but equally effective, security measure that may be implemented in its place.

(C) If the DoD CIO has previously adjudicated the contractor’s requests indicating that a requirement is not applicable or that an alternative security measure is equally effective, a copy of that approval shall be provided to the Contracting Officer when requesting its recognition under this contract.

(D) If the Contractor intends to use an external cloud service provider to store, process, or transmit any covered defense information in performance of this contract, the Contractor shall require and ensure that the cloud service provider meets security requirements equivalent to those established by the Government for the Federal Risk and Authorization Management Program (FedRAMP) Moderate baseline (https://www.fedramp.gov/documents-templates/) and that the cloud service provider complies with requirements in paragraphs (c) through (g) of this clause for cyber incident reporting, malicious software, media preservation and protection, access to additional information and equipment necessary for forensic analysis, and cyber incident damage assessment.

(3) Apply other information systems security measures when the Contractor reasonably determines that information systems security measures, in addition to those identified in paragraphs (b)(1) and (2) of this clause, may be required to provide adequate security in a dynamic environment or to accommodate special circumstances (e.g., medical devices) and any individual, isolated, or temporary deficiencies based on an assessed risk or vulnerability. These measures may be addressed in a system security plan.

(c) Cyber incident reporting requirement.

(1) When the Contractor discovers a cyber incident that affects a covered contractor information system or the covered defense information residing therein, or that affects the contractor’s ability to perform the requirements of the contract that are designated as operationally critical support and identified in the contract, the Contractor shall-

(i) Conduct a review for evidence of compromise of covered defense information, including, but not limited to, identifying compromised computers, servers, specific data, and user accounts. This review shall also include analyzing covered contractor information system(s) that were part of the cyber incident, as well as other information systems on the Contractor’s network(s), that may have been accessed as a result of the incident in order to identify compromised covered defense information, or that affect the Contractor’s ability to provide operationally critical support; and

(ii) Rapidly report cyber incidents to DoD at https://dibnet.dod.mil.

(2) Cyber incident report. The cyber incident report shall be treated as information created by or for DoD and shall include, at a minimum, the required elements at https://dibnet.dod.mil.

(3) Medium assurance certificate requirement. In order to report cyber incidents in accordance with this clause, the Contractor or subcontractor shall have or acquire a DoD-approved medium assurance certificate to report cyber incidents. For information on obtaining a DoD-approved medium assurance certificate, see https://public.cyber.mil/eca/.

(d) Malicious software. When the Contractor or subcontractors discover and isolate malicious software in connection with a reported cyber incident, submit the malicious software to DoD Cyber Crime Center (DC3) in accordance with instructions provided by DC3 or the Contracting Officer. Do not send the malicious software to the Contracting Officer.

(e) Media preservation and protection. When a Contractor discovers a cyber incident has occurred, the Contractor shall preserve and protect images of all known affected information systems identified in paragraph (c)(1)(i) of this clause and all relevant monitoring/packet capture data for at least 90 days from the submission of the cyber incident report to allow DoD to request the media or decline interest.

(f) Access to additional information or equipment necessary for forensic analysis. Upon request by DoD, the Contractor shall provide DoD with access to additional information equipment that is necessary to conduct a forensic analysis.

(g) Cyber incident damage assessment activities. If DoD elects to conduct a damage assessment, the Contracting Officer will request that the Contractor provide all of the damage assessment information gathered in accordance with paragraph (e) of this clause.

(h) DoD safeguarding and use of contractor attributional/proprietary information. The Government shall protect against the unauthorized use or release of information obtained from the contractor (or derived from information obtained from the contractor) under this clause that includes contractor attributional/proprietary information, including such information submitted in accordance with paragraph (c). To the maximum extent practicable, the Contractor shall identify and mark attributional/proprietary information. In making an authorized release of such information, the Government will implement appropriate procedures to minimize the contractor attributional/proprietary information that is included in such authorized release, seeking to include only that information that is necessary for the authorized purpose(s) for which the information is being released.

(i) Use and release of contractor attributional/proprietary information not created by or for DoD. Information that is obtained from the contractor (or derived from information obtained from the contractor) under this clause that is not created by or for DoD is authorized to be released outside of DoD-

(1) To entities with missions that may be affected by such information;

(2) To entities that may be called upon to assist in the diagnosis, detection, or mitigation of cyber incidents;

(3) To Government entities that conduct counterintelligence or law enforcement investigations;

(4) For national security purposes, including cyber situational awareness and defense purposes (including with Defense Industrial Base (DIB) participants in the program at 32 CFR part 236); or

(5) To a support services contractor (“recipient”) that is directly supporting Government activities under a contract that includes the clause at 252.204- 7009, Limitations on the Use or Disclosure of Third-Party Contractor Reported Cyber Incident Information.

(j) Use and release of contractor attributional/proprietary information created by or for DoD. Information that is obtained from the contractor (or derived from information obtained from the contractor) under this clause that is created by or for DoD (including the information submitted pursuant to paragraph (c) of this clause) is authorized to be used and released outside of DoD for purposes and activities authorized by paragraph (i) of this clause, and for any other lawful Government purpose or activity, subject to all applicable statutory, regulatory, and policy based restrictions on the Government’s use and release of such information.

(k) The Contractor shall conduct activities under this clause in accordance with applicable laws and regulations on the interception, monitoring, access, use, and disclosure of electronic communications and data.

(l) Other safeguarding or reporting requirements. The safeguarding and cyber incident reporting required by this clause in no way abrogates the Contractor’s responsibility for other safeguarding or cyber incident reporting pertaining to its unclassified information systems as required by other applicable clauses of this contract, or as a result of other applicable U.S. Government statutory or regulatory requirements.

(m) Subcontracts. The Contractor shall-

(1) Include this clause, including this paragraph (m), in subcontracts, or similar contractual instruments, for operationally critical support, or for which subcontract performance will involve covered defense information, including subcontracts for commercial products or commercial services, without alteration, except to identify the parties. The Contractor shall determine if the information required for subcontractor performance retains its identity as covered defense information and will require protection under this clause, and, if necessary, consult with the Contracting Officer; and

(2) Require subcontractors to-

(i) Notify the prime Contractor (or next higher-tier subcontractor) when submitting a request to vary from a NIST SP 800-171 security requirement to the Contracting Officer, in accordance with paragraph (b)(2)(ii)(B) of this clause; and

(ii) Provide the incident report number, automatically assigned by DoD, to the prime Contractor (or next higher-tier subcontractor) as soon as practicable, when reporting a cyber incident to DoD as required in paragraph (c) of this clause.

(End of clause)

252.211-7003 Item Unique Identification and Valuation. (Jan 2023)

As prescribed in 211.274-5(a), use the following clause:

ITEM UNIQUE IDENTIFICATION AND VALUATION (JAN 2023)

(a) Definitions. As used in this clause-

"Automatic identification device" means a device, such as a reader or interrogator, used to retrieve data encoded on machine-readable media.

"Concatenated unique item identifier" means-

(1) For items that are serialized within the enterprise identifier, the linking together of the unique identifier data elements in order of the issuing agency code, enterprise identifier, and unique serial number within the enterprise identifier; or

(2) For items that are serialized within the original part, lot, or batch number, the linking together of the unique identifier data elements in order of the issuing agency code; enterprise identifier; original part, lot, or batch number; and serial number within the original part, lot, or batch number.

"Data matrix" means a two-dimensional matrix symbology, which is made up of square or, in some cases, round modules arranged within a perimeter finder pattern and uses the Error Checking and Correction 200 (ECC200) specification found within International Standards Organization (ISO) /International Electrotechnical Commission (IEC) 16022.

"Data qualifier" means a specified character (or string of characters) that immediately precedes a data field that defines the general category or intended use of the data that follows.

"DoD recognized unique identification equivalent" means a unique identification method that is in commercial use and has been recognized by DoD.

All DoD recognized unique identification equivalents are listed at https://www.acq.osd.mil/asda/dpc/ce/ds/unique-id.html.

"DoD item unique identification" means a system of marking items delivered to DoD with unique item identifiers that have machine-readable data elements to distinguish an item from all other like and unlike items. For items that are serialized within the enterprise identifier, the unique item identifier shall include the data elements of the enterprise identifier and a unique serial number. For items that are serialized within the part, lot, or batch number within the enterprise identifier, the unique item identifier shall include the data elements of the enterprise identifier; the original part, lot, or batch number; and the serial number.

" Enterprise " means the entity (e.g., a manufacturer or vendor) responsible for assigning unique item identifiers to items.

" Enterprise identifier" means a code that is uniquely assigned to an enterprise by an issuing agency.

"Government's unit acquisition cost" means-

(1) For fixed-price type line, subline, or exhibit line items, the unit price identified in the contract at the time of delivery;

(2) For cost-type or undefinitized line, subline, or exhibit line items, the Contractor's estimated fully burdened unit cost to the Government at the time of delivery; and

(3) For items produced under a time-and-materials contract, the Contractor's estimated fully burdened unit cost to the Government at the time of delivery.

"Issuing agency" means an organization responsible for assigning a globally unique identifier to an enterprise, as indicated in the Register of Issuing Agency Codes for ISO/IEC 15459, located at http://www.aimglobal.org/?Reg_Authority15459.

"Issuing agency code" means a code that designates the registration (or controlling) authority for the enterprise identifier.

"Item" means a single hardware article or a single unit formed by a grouping of subassemblies, components, or constituent parts.

" Lot or batch number" means an identifying number assigned by the enterprise to a designated group of items, usually referred to as either a lot or a batch, all of which were manufactured under identical conditions.

"Machine-readable" means an automatic identification technology media, such as bar codes, contact memory buttons, radio frequency identification, or optical memory cards.

"Original part number" means a combination of numbers or letters assigned by the enterprise at item creation to a class of items with the same form, fit, function, and interface.

"Parent item" means the item assembly, intermediate component, or subassembly that has an embedded item with a unique item identifier or DoD recognized unique identification equivalent.

"Serial number within the enterprise identifier" means a combination of numbers, letters, or symbols assigned by the enterprise to an item that provides for the differentiation of that item from any other like and unlike item and is never used again within the enterprise.

"Serial number within the part, lot, or batch number" means a combination of numbers or letters assigned by the enterprise to an item that provides for the differentiation of that item from any other like item within a part, lot, or batch number assignment.

"Serialization within the enterprise identifier" means each item produced is assigned a serial number that is unique among all the tangible items produced by the enterprise and is never used again. The enterprise is responsible for ensuring unique serialization within the enterprise identifier.

"Serialization within the part, lot, or batch number" means each item of a particular part, lot, or batch number is assigned a unique serial number within that part, lot, or batch number assignment. The enterprise is responsible for ensuring unique serialization within the part, lot, or batch number within the enterprise identifier.

"Type designation" means a combination of letters and numerals assigned by the Government to a major end item, assembly or subassembly, as appropriate, to provide a convenient means of differentiating between items having the same basic name and to indicate modifications and changes thereto.

"Unique item identifier" means a set…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .