SOW Attachment - SaaS Contract Language and Price Schedule - FY25 Rev 6.docx
DOCX document 48 KB Posted
- Attached to
- DA10--VISN 5 HTM Competency Software (as a Service) Federal contract opportunity
- Solicitation number
- 36C24525Q0803
About this file
This document is a Statement of Work (SOW) Attachment for a SaaS Contract Language and Price Schedule for FY25, specifically focusing on FedRAMP and VA authorization requirements for cloud services. The document provides detailed guidance for three scenarios of FedRAMP authorization: 1) solutions not currently FedRAMP authorized, 2) solutions FedRAMP authorized but not VA authorized, and 3) solutions FedRAMP and VA authorized.
Key requirements include compliance with Federal Information Security Management Act (FISMA), completion of FedRAMP System Security Plan (SSP), VA Implementation Diagram, Third-Party Assessment Organization (3PAO) Security Assessment Plan and Report, and continuous monitoring activities. The price schedule includes line items for FedRAMP authorization processes, with different pricing structures based on the authorization status. The opportunity is associated with the Department of Veterans Affairs Veterans Health Administration Veterans Integrated Service Network 5 (VISN 5), specifically for a DA10 HTM Competency Software as a Service solicitation (Solicitation Number: 36C24525Q0803).
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| Questions and Answers.docx | DOCX document | |
| 36C24525Q0803.docx | DOCX document |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
SaaS Contract Language and Price Schedule Purpose: The purpose of this document is to identify the specific SaaS Contract Language that should be utilized when exercising a SaaS contract based on current FedRAMP and VA authorization status. Please include the relevant section based on the level of authorization needed for the chosen solution and reach out to the Digital Transformation Center for specific questions, when necessary.
Contents
| SaaS FedRAMP Requirements | 2 |
| If the solution is not FedRAMP authorized: | 2 |
| Deliverables: | 4 |
| If the solution is FedRAMP Authorized but not VA FedRAMP Authorized | 5 |
| Deliverables: | 6 |
| If the solution is FedRAMP Authorized and VA FedRAMP Authorized | 7 |
| Deliverables: | 7 |
| No VA Data Language Requirements | 8 |
| Price Schedule Example | 10 |
Section 1: If the solution is not FedRAMP Authorized
Attachment A: SaaS FedRAMP Requirements (Everything included in this section will be added to the PD/PWS aside from the No VA Data section. The No VA Data section is not applicable.)
If the solution is not FedRAMP authorized:
1. The information system solution selected by the Contractor shall comply with the Federal Information Security Management Act (FISMA).
2. The Contractor shall comply with FedRAMP requirements Low Impact as mandated by Federal laws and policies, including making available any documentation, physical access, and logical access needed to support this requirement.
3. The Contractor shall provide a SaaS product as defined by the following criteria: Software as a Service (SaaS) is an application delivery model in which the application is hosted on a cloud infrastructure outside the security boundary of VA and is provided to the Cloud Service Customer (CSC) over the internet. The CSC uses the SaaS offering via a thin-client interface, such as a web-browser or a program interface. The CSC subscribes to the SaaS offering and is only responsible for minor in-app customizations. The Cloud Service Provider (CSP) offering the application is responsible for management of the application, safeguarding of data stored or processed by the application, and all elements of the underlying infrastructure. Additionally, the CSP is responsible for all on-going compliance.
In order to qualify as SaaS for use at VA, and to align with Federal Risk and Authorization Management Program (FedRAMP) requirements, the hosting for the offering must conform to the NIST 800-145 definition of Cloud Computing and thus contain following key characteristics:
· On-Demand Self-Service: The CSP fully automates the provisioning of both the customer interface and the underlying cloud components of the SaaS offering. In some cases, to the CSP may provision internal resources manually, while providing the CSC an automated interface to request and track the service.
· Broad Network Access: The SaaS capabilities are available over the internet or over a network that is available from all access points the CSC requires. The SaaS offering is accessible through common platforms (e.g., mobile phones, tablets, laptops, and workstations).
· Resource Pooling: The computing infrastructure supporting the SaaS offering is shared among more than one CSC using a multi-tenant model, and resources are dynamically assigned depending on customer demand.
· Rapid Elasticity: Computing capabilities are automatically provisioned and released in a manner that scales with customer demand. In some cases, the scaling of resources may not be fully automated, but it should be fast enough to support the needs of the CSC, which the CSC would have to define.
· Measured Service: Resource usage, such as storage, processing, bandwidth, and user activity are measured and reported on in a manner that is relevant to the SaaS offering.
4. Following guidance from the Federal CIO, VA will utilize existing JAB ATO or agency ATO issued by another agency as a starting point for FedRAMP requirements. If neither of those exist, VA will sponsor The Cloud Service Provider for a FedRAMP Authorization. VA will be using the FedRAMP baselines as a starting point, since they are specifically tailored for cloud services.
5. The Contractor shall, where applicable, assist with the VA ATO Process to help achieve agency authorization of the cloud service or migrated application at the impact level required by VA to utilize the product. For this solution the required impact level is: Low Impact
6. The Contractor shall comply with FedRAMP requirements surrounding data location within the Continental United States. FedRAMP specifies data location requirements in the High Baseline as part of control SA-9 (5); however, FedRAMP does not provide or specify data location requirements for other baselines.
7. The Contractor shall complete a FedRAMP System Security Plan (SSP) and supporting documentation including required attachments within 75 calendar days after contract award. (If Data Security Categorization is High Impact, this will be due 94 calendar days after contract award.)
8. The Contractor shall work with a VA Subject Matter Expert to develop a specific system boundary diagram including any integration and connectivity components for VA use. This will be known as the VA Implementation Diagram (VAID) and will demonstrate the proposed implementation of this system at VA. The Contractor shall complete this deliverable with VA within 10 calendar days of contract award.
9. The Contractor shall complete a Third-Party Assessment Organization (3PAO) Security Assessment Plan (SAP) within 90 calendar days after contract award. (If Data Security Categorization is High Impact, this will be due after 113 calendar days after contract award.)
10. The Contractor shall complete a 3PAO Security Assessment Report (SAR) within 90 calendar days after the SSP is accepted by VA. (If Data Security Categorization is High Impact, this will be due 113 calendar days after the SSP is accepted by VA.)
11. The Contractor shall work with VA Subject Matter Experts to test the validity of the Incident Response Plan (IRP) and ensure proper troubleshooting of issues that may arise. This should be completed within 30 calendar days of the SSP being delivered.
12. The Contractor shall afford VA access to the Contractor’s and Cloud Service Provider’s (CSP) facilities, installations, technical capabilities, operations, documentation, records, and databases.
13. If new or unanticipated vulnerabilities are discovered by either VA or the Contractor, or if existing safeguards have ceased to function, the discoverer shall immediately bring the situation to the attention of the other party in accordance with Addendum B, VA Information, and Information System Security/Privacy Language.
14. The Contractor shall comply with data management requirements.
15. Successful issuance of a VA ATO will be required before live VA data can be used in the system.
16. The Contractor shall participate in FedRAMP Continuous Monitoring activities as outlined by FedRAMP’s Continuous Monitoring Strategy Guide found on the FedRAMP website.
17. The Contractor shall participate in monthly Agency and FedRAMP Sustainment meetings following the granting of a VA ATO.
18. The Contractor shall provide continuous monitoring activities including, but not limited to scans, security artifacts, and monthly Plan of Action and Milestones (POAM) reports as outlined by VA and FedRAMP requirements.
Deliverables:
A. FedRAMP System Security Plan (SSP) and required Attachments B. VA Implementation Diagram C. 3PAO Security Assessment Plan (SAP) D. 3PAO Security Assessment Report (SAR) E. Plan of Action and Milestones Monthly Reports.
Section 2: If the solution is FedRAMP Authorized but not VA Authorized
(Everything included in this section will be added to the PD/PWS) If the solution is FedRAMP Authorized but not VA Authorized:
1. The information system solution selected by the Contractor shall comply with the Federal Information Security Management Act (FISMA)
2. The Contractor shall comply with FedRAMP requirements as mandated by Federal laws and policies, including making available any documentation, physical access, and logical access needed to support this requirement
3. The system must be FedRAMP Authorized at no less than the <<Insert Impact Level from the Data Security Categorization. This should be done by DTC.>>
4. The Contractor shall, where applicable, assist with the VA ATO Process to help achieve agency authorization of the cloud service or migrated application.
5. The Contractor shall provide confirmation of their FedRAMP System Security Plan (SSP) and supporting documentation completion via their repository ID number and a link for VA to download the SSP and all required artifacts within 5 calendar days of contract award.
6. The Contractor shall work with a VA Subject Matter Expert to develop a specific system boundary diagram including any integration and connectivity components for VA use. This will be known as the VA Implementation Diagram (VAID) and will demonstrate the proposed implementation of this system at VA. The Contractor shall complete this deliverable with VA within 10 calendar days of contract award.
7. The Contractor shall provide the results of their most recent Third-Party Assessment Organization (3PAO) Security Assessment Plan (SAP) within 10 calendar days of contract award.
8. The Contractor shall complete a 3PAO Security Assessment Report (SAR) within 10 calendar days after the SSP is accepted by VA.
9. The Contractor shall provide VA with the most recent monthly scans for the production environment within the authorization boundary and their scan upload schedule for FedRAMP within 30 calendar days of contract award.
10. The Contractor shall provide their availability to participate in monthly continuous monitoring meetings to be scheduled following successful VA ATO within 30 calendar days of contract award.
11. The Contractor shall work with VA Subject Matter Experts to test the validity of the Incident Response Plane (IRP) and ensure proper troubleshooting of issues that may arise. This should be completed within 30 calendar days of the SSP being delivered.
12. If new or unanticipated vulnerabilities are discovered by either VA or the Contractor, or if existing safeguards have ceased to function, the discoverer shall immediately bring the situation to the attention of the other party in accordance with Addendum B, VA Information and Information System Security/Privacy Language.
13. The Contractor shall comply with data management requirements.
14. Successful issuance of a VA ATO will be required before live VA data can be used in the system.
15. The Contractor shall participate in FedRAMP Continuous Monitoring activities as outlined by FedRAMP’s Continuous Monitoring Strategy.
16. The Contractor shall participate in monthly Agency and FedRAMP Sustainment meetings following the granting of a VA ATO.
17. The Contractor shall provide continuous monitoring activities including, but not limited to scans, security artifacts, and monthly Plan of Action and Milestones (POAM) reports as outlined by VA and FedRAMP requirements.
Deliverables:
A. FedRAMP System Security Plan (SSP) and required Attachments B. VA Implementation Diagram C. 3PAO Security Assessment Plan (SAP) D. 3PAO Security Assessment Report (SAR) E. Plan of Action and Milestones Monthly Reports.
Section 3: If the solution is FedRAMP Authorized and VA Authorized
(Everything included in this section will be added to the PD/PWS) If the solution is FedRAMP Authorized and VA Authorized:
1. The information system solution selected by the Contractor shall comply with the Federal Information Security Management Act (FISMA) and have a current VA authorization.
2. The Contractor shall comply with FedRAMP requirements as mandated by Federal laws and policies, including making available any documentation, physical access, and logical access needed to support this requirement.
3. The FedRAMP Authorization level and existing VA ATO should be no less than the level required for this use case which has been defined as <<Insert Impact Level from the Data Security Categorization. This should be done by DTC.>>
4. The Contractor shall, where applicable, assist with the VA ATO Sustainment Process to help maintain health and quality of agency authorization of the cloud service or migrated application.
5. The Contractor shall exclusively provide licenses and/or accounts to FedRAMP authorized and VA authorized environments.
6. The Contractor shall afford VA access to the Contractor’s and Cloud Service Provider’s (CSP) facilities, installations, technical capabilities, operations, documentation, records, and databases.
7. If new or unanticipated vulnerabilities are discovered by either VA or the Contractor, or if existing safeguards have ceased to function, the discoverer shall immediately bring the situation to the attention of the other party in accordance with Addendum B, VA Information and Information System Security/Privacy Language. VA Privacy and Security deliverables as directed by the VA System owner.
8. The Contractor shall comply with data management requirements.
9. Successful issuance of a VA ATO will be required before live VA data can be used in the system.
10. The Contractor shall participate in FedRAMP Continuous Monitoring activities as outlined by FedRAMP’s Continuous Monitoring Strategy Guide found on the FedRAMP Website.
11. The Contractor shall participate in monthly Agency and FedRAMP Sustainment meetings following the granting of a VA ATO.
Deliverables:
A. 3PAO Security Assessment Report (SAR) B. Continuous Monitoring Monthly Scans C. Plan of Action and Milestones Monthly Reports.
Section 4: If the solution is identified as a No VA Data System No VA Data:
This determination will come from the DTC and Information System Security Engineers (ISSE) Team within Cloud Security. This language is not applicable without DTC approval and a formal No VA Data Memo.
Please insert the following language into the requirements section once a No VA Data Memo has been issued by DTC:
1. Software-as-a-Service (SaaS) Solution The Contractor shall provide a SaaS solution that does not have direct connections or interfaces to VA systems or networks. VA providers shall access the solution in a view-only mode or with limited functionality. The Contractor shall ensure that no data is created, collected, processed, maintained, disseminated, or disposed of on behalf of the VA. The Contractor shall comply with OMB Circular A-130, which defines federal-owned data as information owned or managed by the federal government, including information collected, maintained, and shared for government functions.
a. Data Handling for Veterans Using Devices
· User Consent: Veteran users who use the product shall consent to share their data, which may include Personally Identifiable Information (PII) and Protected Health Information (PHI), directly with the SaaS provider.
· Published Terms: The SaaS provider shall have published terms and conditions for user consent.
· Data Ownership: All data processed by the SaaS provider shall be owned by the SaaS provider or the Veteran user.
· Revocation: Veteran users shall have the ability to revoke data sharing with the SaaS provider at any point.
b. Data Sharing Revocation
· For systems classified as "No VA Data," the Veteran is entering directly into a relationship with the SaaS provider and has granted their VA medical team one-way, view-only access to read the data.
· The medical team may then pull information into the Veteran's/patient’s medical record.
· The Veteran/patient may at any time revoke sharing with the SaaS provider and/or their medical care team.
· In the event that data sharing is revoked, the medical provider will retain data already shared but will immediately stop collecting additional data from the SaaS provider and veteran.
· VA shall make the Veteran, Caregiver or Veteran Representative aware of the disclosure of data to the third party and their ownership of the data.
PRICE SCHEDULE EXAMPLE
*This is an example only and the Cloud Service Customer (CSC) should work with their CO/COR directly to complete the Price Schedule.
Base Period – FedRAMP Authorization and VA Authorization The period of performance for this effort shall be up to 12 months in accordance with (IAW) Section 4.1 of the Product Description.
| CLIN |
| Description |
| Qty |
| Unit |
| Unit Price |
| Extended Price |
| 0001 |
| FedRAMP approval for (add SaaS product Name and FISMA categorization)– Solution is Not FedRAMP Authorized or VA FedRAMP Authorized. |
*If a vendor’s solution is not FedRAMP Authorized or VA FedRAMP Authorized the vendor shall complete CLIN 0001 and SLINS 0001AA-0001AD.
CLINs 0002 and 0003 (and associated SLINs) shall be $0.00.
| 1 |
| LO |
| Not Separately Priced (NSP) |
| NSP |
| 0001AA |
| FedRAMP System Security Plan (SSP) and supporting documentation. |
Due 75 calendar days after contract award. (If Data Security Categorization is High Impact, this will be due 94 calendar days after contract award.)
*10% of the FedRAMP Approved Solution value. VA does not pay for FedRAMP Authorization fees and/or vendor acquired costs.
| 1 |
| LO |
| *$ |
| *$ |
| 0001AB |
| VA Implementation Diagram: |
VA specific architecture diagram demonstrating proposed implementation of the system at VA.
Due 10 calendar days after contract award.
| 1 |
| LO |
| NSP |
| NSP |
0001AC
Third Party Assessment Organization (3PAO) Security Assessment Plan (SAP)
Due 90 calendar days after the SSP is accepted by VA. (If Data Security Categorization is High Impact, this will be due 113 calendar days after the SSP is accepted by VA.)
*10% of the FedRAMP Approved Solution value. VA does not pay for FedRAMP Authorization fees and/or vendor acquired costs.
| 1 |
| LO |
| *$ |
| *$ |
| 0001AD |
| 3PAO Security Assessment Report (SAR) |
Due 90 calendar days after contract award. (If Data Security Categorization is High Impact, this will be due 113 calendar days after contract award.)
*10% of the FedRAMP (add FISMA impact) Approved Solution value. VA does not pay for FedRAMP Authorization fees and/or vendor acquired costs.
| 1 |
| LO |
| *$ |
| *$ |
| 0002 |
| FedRAMP approval for the (add SaaS product Name and FISMA categorization)– Solution is FedRAMP Authorized but NOT VA FedRAMP Authorized. |
* If a vendor’s solution is FedRAMP Authorized but not VA FedRAMP Authorized, the vendor shall complete CLIN 0002 and SLINS 0002AA-0002AD.
CLINs 0001 and 0003 (and associated SLINs) shall be $0.00.
| 1 |
| LO |
| NSP |
| NSP |
| 0002AA |
| IRP Table Top scenario |
Contractor shall work with assigned VA SME to develop a VA specific Incident Response Plan (IRP) and perform an IRP Table Top Exercise with VA Stakeholders. This should be completed within 30 calendar days of the SAR being delivered.
| 1 |
| LO |
| NSP |
| NSP |
| 0002AB |
| VA Implementation Diagram |
The Contractor shall develop a VA specific system boundary diagram including any integration and connectivity components that will be known as a VA Implementation Diagram (VAID) demonstrating the proposed implementation of this system at VA. The Contractor shall provide the VAID within 10 calendar days of contract award.
| 0002AC |
| FedRAMP SSP and supporting documentation. |
The Contractor shall provide confirmation of their FedRAMP System Security Plan (SSP) and supporting documentation completion via their repository ID number and a link for VA to download the SSP and all required artifacts within 5 calendar days of contract award.
| 1 |
| LO |
| 0002AC |
| 3PAO SAP |
The Contractor shall provide the results of their most recent Third-Party Assessment Organization (3PAO) Security Assessment Plan (SAP) within 10 calendar days of contract award.
| 1 |
| LO |
| 0002AD |
| 3PAO SAR |
The Contractor shall complete a 3PAO Security Assessment Report (SAR) within 10 calendar days after the SSP is accepted by VA.
| 1 |
| LO |
| 0003 |
| FedRAMP approval for (add SaaS product Name and FISMA categorization)– If Solution is FedRAMP Authorized and VA FedRAMP Authorized. |
* In the event that the proposed product is already FedRamp Authorized and VA FedRamp Authorized and proposed pricing is not required, please list $0.00 for CLIN 0001, 0002 and 0003 (and associated SLINs).
| 1 |
| LO |
| NSP |
| NSP |
| 0003AA |
| Dates for Current ATO expiration. |
Due at time of award.
| 1 |
| LO |
| NSP |
| NSP |
| 0003AB |
| Most recent monthly Plan of Action Milestones finding reports. |
Due at time of award.
| 1 |
| LO |
| NSP |
| NSP |
| Total Base Period |
| $ |
Base Period Optional Task In accordance with FAR 52.217-7, “Option for Increased Quantity-Separately Priced Line Item,” this Optional Task may be exercised one time during the base period of performance once solution is FedRAMP Authorized and VA FedRAMP Authorized. If exercised, the Period of Performance shall be up to 12 months. Work shall not commence until, and unless, a formal modification is issued by the Contracting Officer.
| CLIN |
| Description |
| Qty |
| Unit |
| Unit Price |
| Extended Price |
| 0004 |
| FedRAMP (insert FISMA Impact) Approved Solution in accordance with (IAW) Product Description (PD) Section 1.1. |
*70% of FedRAMP (add FISMA impact) Approved Solution
*100% if Solution is already FedRAMP Authorized and VA FedRAMP Authorized.
| up to 12 |
| MO |
| *$ |
| *$ |
File details come from the government source that posted it. Updated .