SOW Revised ICIDS Rev-6 rev 10APR26.pdf
PDF 365 KB Posted
- Attached to
- Physical Access Control System (PACS) and Intrusion Detection System (IDS) Upgrade Federal contract opportunity
- Solicitation number
- W91RUS26QA026
About this file
This is a Performance Work Statement (PWS) for a Physical Access Control System (PACS) and Intrusion Detection System (IDS) upgrade at United States Army Signal Activity (USASA)-Belvoir, Fort Belvoir, Virginia. The contractor shall provide a full-scope, turnkey replacement, installation, configuration, and commissioning of the existing PACS and IDS for a Nuclear Command, Control, and Communications (NC3) facility rated environment. The system must control access to 12 doors comprising five 1800-pound magnetic locks for external doors and seven 1200-pound magnetic locks for internal doors. The proximity card readers must be compatible with CAC/PIV credentials and comply with FIPS-201 and HSPD-12 standards. All system components must be compliant with DoD Directive 5200.08-R, NIST SP 800-53, and must support multi-factor authentication including smart card, PIN entry, and future biometric integration. Hardware must feature tamper resistance with immediate alarm generation upon unauthorized access attempts and utilize AES 256-bit encryption for all communications between readers and control panels.
The contract is structured as a Firm Fixed Price (FFP) commercial service contract with a one-year base period and three option years for sustainment services. The system must be installed, tested, and commissioned no later than 120 days after award, with equipment delivery required by day 90. Key deliverables include a Project Management and Quality Control Plan (15 days), Final System Design Document (45 days), Installation and Commissioning Plan (60 days), System Administrator and Operator Training (prior to system go-live), and Final As-Built Drawings and System Documentation (upon final system acceptance). Performance requirements mandate 99.95% system uptime, alert response times under 2 seconds, 100% successful PIV authentication, and immediate tamper detection alarms. Post-installation technical support must be provided for one year with a 24-hour response requirement. Sustainment services include preventive maintenance conducted per manufacturer specifications and onsite corrective maintenance with a 2-hour initial acknowledgment requirement and 48-hour onsite response requirement if remote resolution fails. The contractor must meet security and base access requirements per Army Regulation 190-13, including personnel vetting and background checks submitted 10 days prior to work commencement.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| SF30 W91RUS26QA026 Amendment 0002.pdf | ||
| Atch 0003 QA Responses.pdf | ||
| SF30 W91RUS26QA026 Amendment0001.pdf | ||
| Atch 2 Redacted JnA.pdf | ||
| SF 1449 Solicitation - W91RUS26QA026.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Performance Work Statement
Physical Access Control System (PACS) and Intrusion Detection System (IDS) Upgrade
United States Army Signal Activity (USASA)-Belvoir
8575 John J. Kingman Rd. Bldg. 2310
Fort Belvoir, VA 22060
1.0. Introduction and Background
The United States Army Signal Activity (USASA)-Belvoir requires a non-personnel services contract to provide a full-scope, turnkey solution for the replacement, installation, configuration, and commissioning of its existing Physical Access Control System (PACS) and Intrusion Detection
System (IDS). The facility requires a solution rated for a Nuclear Command, Control, and
Communications (NC3) environment, demanding the highest levels of security, reliability, and compliance. The new integrated system must be fully compliant with all current Department of
Defense (DoD), Federal, and Army regulations to protect critical national security assets, personnel, and information.
2.0. Scope of Work
The Contractor shall provide a comprehensive access control system to include the install, reconfigure, and test a turn-key solution for a Stand Alone Security Management System (SMS)
DAQ Access Control System (ACS) in accordance with statement of work for twelve (12) doors, five (5) shall be 1800lbs magnetic locks for all external doors and seven (7) 1200lbs magnetic locks for the specified internal doors. This system will replace the existing ACS in Building 2310 and will operate as a Stand-Alone system at Fort Belvoir, VA. The Proximity Card Readers will be compatible with CAC/PIV and will comply with FIPS-201 and HSPD-12, featuring the ability to read both proximity and CAC/PIV cards. See Exhibit-A (Floor Layout) and Attachment 1.
3.0. Deliverables
The Contractor shall provide all project management, supervision, engineering, labor, materials, equipment, and transportation necessary to deliver a complete and fully operational PACS and
IDS. The scope of this effort includes:
3.1. System Design & Engineering: Develop a comprehensive system design that meets all requirements outlined in this PWS.
3.1.1. Deliverables
Deliverables Due Date (After Contract Award)
Project Management and Quality Control Plan 15 Days
Final System Design Document 45 Days
Installation and Commissioning Plan 60 Days
Equipment Delivery 90 Days
System Administrator and Operator Training Prior to System Go-Live
Final As-Built Drawings and System
Documentation
Upon Final System Acceptance
3.2. Materials and Equipment: Upon award, materials will be procured and delivered to the Place of Performance within 90 days. Once all equipment has been received, personnel will coordinate with the COR to schedule mobilization for installation.
3.3. System Decommissioning and Removal: Decommission and remove the legacy PACS and
IDS hardware. The Contractor shall provide removed equipment to the Government for disposal.
3.4. Installation: Install all new system components, including but not limited to, control panels, servers, workstations, access control readers, door hardware, intrusion sensors, and associated cabling.
3.5. Configuration and Integration: Configure all software and hardware to create a single, seamlessly integrated security platform.
3.6. Commissioning and Testing: Conduct exhaustive system testing to verify that all functional, performance, and security requirements are met.
3.7. Training: Provide comprehensive training for system administrators and operators.
3.8. Documentation: Deliver complete system documentation, including as-built drawings and operational manuals.
3.9. Technical Support: The Contractor shall deliver technical support for a period of one (1) year after successful installation. A response either by phone or on-site shall be provided within 24 hours of a service request.
4.0. Performance Requirements
The fully commissioned system shall meet the following performance standards:
Requirement Standard Verification Method
System Uptime 99.95% operational availability.
System logs during 30-day acceptance test.
Alert Response
Time
All alarm and access events displayed at the monitoring station in under 2 seconds.
Scripted performance testing.
PIV
Authentication
100% successful authentication using valid
PIV cards and PINs.
Live testing with a sample set of PIV cards.
Tamper
Detection
All tamper events generate an immediate, high-priority alarm.
Physical testing of a sample set of devices.
5.0. Technical Requirements, Regulatory, and Policy Compliance
The proposed solution must be a unified platform that meets the following specific compliance, authentication, and security standards. The system, including all hardware and software components, must be fully compliant with the latest versions of the following directives and standards:
5.1. NC3 Facility Rating: All components shall be rated and suitable for the stringent operational and security demands of an NC3 facility.
5.1.1. DoD Directive 5200.08-R: The system must comply with the DoD Physical Security
Program regulations.
5.1.2. NIST SP 800-53: The system must meet the applicable security and privacy controls for high-impact federal information systems.
5.1.3. FIPS 201: The system must be capable of reading, validating, and using Personal Identity
Verification (PIV) credentials as a primary authentication factor.
5.1.4. HSPD-12: The solution must be fully compliant with the policy for a common identification standard for Federal employees and contractors.
5.2. Authentication and Access Control Features
Authentication is a critical component of this system and must adhere to the following:
5.2.1. Multi-Factor Authentication (MFA): The system must enforce MFA for access to all controlled areas.
5.2.2. Keypad Reader Requirements: All keypad readers must, at a minimum, support three-factor authentication combining:
➢ What you have: Smart card (PIV, CAC, or another approved credential).
➢ What you know: Personal Identification Number (PIN) entered on the keypad.
➢ What you are: The system must be capable of integrating biometric readers in the future.
5.3. Hardware Security and Encryption
All installed hardware, especially endpoint devices like keypad readers, must possess robust physical and data security features.
5.3.1. Tamper Resistance: Keypad readers and control panels must be tamper-resistant, featuring switches and sensors capable of generating an immediate alarm upon detecting unauthorized attempts to open, remove, bypass, or disable the device.
5.3.2. AES Encryption: All communications between readers and the access control panels/system servers must be secured using, at a minimum, Advanced Encryption
Standard (AES) 256-bit encryption.
5.3.3. Secure Credential Storage: Readers and controllers must utilize secure, encrypted memory and processing to prevent the unauthorized access, cloning, or exfiltration of credential data.
6.0. General Information
6.1. Contract Type and Period of Performance.
6.1.1. Type of Contract: The government will award a Firm Fixed Price (FFP) commercial service contract to perform the services as described. An FFP contract has been determined as the most suitable method to meet this requirement, as the organization does not possess the internal personnel or specialized equipment necessary to execute this work.
6.1.2. Contract Structure: The contract will be structured with a base period for the primary installation and multiple option years for continued sustainment.
6.1.2.1. Base Year: 1 year from date of award. The system must be installed, tested, and commissioned NLT 120 days after contract award. The Government acknowledges the 30-day period between estimated equipment arrival (Day 90) and the commissioning deadline. The contractor’s proposal shall include a detailed project plan that demonstrates their capability to meet this expedited timeline.
6.1.2.2. Sustainment Services (Applicable to Base Year and Option Years):
For each exercised option year, the contractor shall provide the necessary maintenance to ensure the continued operational integrity, reliability, and functionality of the system past the initial installation and warranty period (Base
Year). These services shall include:
6.1.2.3. Preventive Maintenance: The contractor shall conduct regularly scheduled inspections, servicing, and testing of all system hardware and software components to identify and correct potential faults before they lead to system failures that shall be conducted in accordance with manufacturer specs.
6.1.2.4. Onsite Maintenance: The contractor shall provide qualified technicians onsite to perform corrective maintenance for any system discrepancies or failures that cannot be resolved remotely, including the troubleshooting, repair, or replacement of malfunctioning components.
On Call Maintenance Table
Obligation Requirement Timeline
Initial
Response
The contractor must acknowledge and begin addressing the reported problem.
Within 2 hours of the initial report.
Remote
Resolution
Attempt
The first course of action is to try and fix the issue from a distance.
(Implied within the 2-hour window)
Onsite
Corrective
Action
If remote resolution fails, the contractor must dispatch qualified technicians to the physical site.
Technicians must be onsite to begin troubleshooting, repair, or replacement within 48 hours of the initial report.
6.1.3. Period of Performance: The Period of Performance (POP) will be for one (1) year from the date of contract award constituting the base year and 3 option years
• Option Year 1 Maintenance: The contractor shall provide maintenance services.
• Option Year 2 Maintenance: The contractor shall provide maintenance services.
• Option Year 3 Maintenance: The contractor shall provide maintenance services.
6.1.4. Quality Control: The contractor shall submit a comprehensive Quality Control Plan (QCP) along with their initial proposal to ensure services are performed in accordance with this PWS.
The contractor shall develop and implement procedures to identify, prevent, and ensure non-recurrence of defective services. The QCP is to be submitted with the contractor’s proposal along with copies to the Contracting Officer and Contracting Officer Representative, within 5 working days when changes are made thereafter. After acceptance of the quality control plan the contractor shall receive the contracting officer’s acceptance in writing of any proposed change to this QCP.
6.1.5. Quality Assurance: The government shall evaluate the contractor’s performance under this contract in accordance with the Quality Assurance Surveillance Plan. This plan is primarily focused on what the Government must do to ensure that the contractor has performed in accordance with the performance standards. It defines how the performance standards will be applied, the frequency of surveillance, and the minimum acceptable defect rate(s).
7.0. General Information
7.1. Place of Performance: The work to be performed under this contract will be performed at:
USASA Ft. Belvoir – Earth Terminal Complex
8575 John J. Kingman Rd., Building 2310
Fort Belvoir, VA 22060
7.2. Base Access. IAW Army Regulation 190-13, Non-Common Access Card (CAC) holding visitors, contractors, vendors, and other personnel as described in paragraph 8-4 of AR 190-13, must have a need validated by Department of Defense (DOD) component for one-time, intermittent, or routine physical access to an Army installation. Visitors will not be granted unescorted installation access without the required identity proofing, vetting against the National
Crime Information Center Interstate Identification Index (NCIC-III). The Installation Commander will, in the absence of a waiver, deny uncleared contractor, subcontractor and visitors unescorted access to the installation based on the results of the NCIC-III check that contains credible derogatory information. Such derogatory information includes, but is not limited to the following:
a. The NCIC III contains criminal arrest information about the individual that causes the installation Commander to determine that individual presents a potential threat to the good order, discipline, or health and safety on the installation.
b. The Installation is unable to verify the individual’s claimed identity in the attempt to gain access.
c. The individual has a current arrest warrant in NCIC, regardless of the offense or violation.
d. The individual is currently barred from entry or access to a federal installation or facility.
e. The individual has been convicted of crimes encompassing sexual assault, armed robbery, rape, child molestation, production or possession of child pornography trafficking in humans, drug possession with the intent to sell or drug distribution.
f. The individual has a US conviction for espionage, sabotage, treason, terrorism or murder.
g. The individual is a registered sex offender.
h. The individual has a felony conviction within the past 10 years, regardless of the offense or violation.
i. The individual has been convicted of a felony firearms or explosives violation.
j. The individual has engaged in acts or activities designed to overthrow the U.S. Government by force.
k. The individual is identified in the Terrorist Screening Database (TSDB) as known to be or suspected of being a terrorist or belonging to an organization with known links to terrorism or support of terrorist activity.
l. Individual is barred from Fort Belvoir.
7.3. Security Requirements: The contractor shall provide complete AHRC TASS Form 1
(Applicant Registration Form) for all personnel providing services under this contract. The
Contractor shall provide the following information of all personnel providing services under this contractor to the Contracting Officer Representative (COR) using Fort Belvoir Vetting, First, Middle, Last Name, social security number, date of birth, place of birth, and full name 10 days prior to commencement of work.
7.4. Physical Security: The contractor shall be responsible for safeguarding all government equipment, information and property provided for contractor use. At the close of each work period, government facilities, equipment, and materials shall be secured.
7.5. Badges. Personnel I.D. badges shall be worn when required by the specific tenant or organization. Those badges will be temporally assigned by that specific tenant or organization.
7.6. Key Control: The Contractor shall establish and implement methods of making sure all keys/key cards issued to the Contractor by the Government are not lost or misplaced and are not used by unauthorized persons. NOTE: All references to keys include key cards. No keys issued to the Contractor by the Government shall be duplicated. The Contractor shall develop procedures covering key control that shall be included in the Quality Control Plan. Such procedures shall include turn-in of any issued keys by personnel who no longer require access to locked areas. The
Contractor shall immediately report any occurrences of lost or duplicate keys/key cards to the
Contracting Officer.
7.7.1. In the event keys, other than master keys, are lost or duplicated, the Contractor shall, upon direction of the Contracting Officer, re-key or replace the affected lock or locks; however, the
Government, at its option, may replace the affected lock or locks or perform re-keying. When the replacement of locks or re-keying is performed by the Government, the total cost of re-keying or the replacement of the lock or locks shall be deducted from the monthly payment due the
Contractor. In the event a master key is lost or duplicated, all locks and keys for that system shall be replaced by the Government and the total cost deducted from the monthly payment due the
Contractor.
7.7.2. The Contractor shall prohibit the use of Government issued keys/key cards by any persons other than the Contractor’s employees. The Contractor shall prohibit the opening of locked areas by Contractor employees to permit entrance of persons other than Contractor employees engaged in the performance of assigned work in those areas, or personnel authorized entrance by the
Contracting Officer.
7.8. Special Qualifications: The Contractor shall field a team whose members possess the requisite experience and certifications for IDS/PACS installation and security systems engineering, coupled with a comprehensive understanding of DoW credentialing and access control policies.
7.10. Identification of Contractor Employees: All contract personnel attending meetings, using
Government telephones, and working in other situations where their contractor status is not obvious to third parties are required to identify themselves as such to avoid creating an impression that they are Government officials. They must also ensure that all documents or reports produced by contractors are suitably marked as contractor products or that contractor participation is appropriately disclosed. Contractor personnel will be required to obtain and wear badges in the performance of this service.
Exhibit A: Floor layout for Building 2310 Ft. Belvoir
Attachment 1. Product List and Description Below (See as listed in Section(s) 2.0 and 4.0)
Exhibit A: Floor Layout
Attachment 1.
Proposed Product List and Description
Description Part Number Quantity
HSS L2 HSS-L2D0000 2
2D 1200lb Maglock 10MAGLOCK5ULDS 3
1D 1200lb Maglock 10MAGLOCK1ULDS 6
RPK40-H, FIPS-201-200 BIT Card Reader H34-10120 18
Emergency Exit button SS2420EX-EN 9
Entro Star 14x12x4.5 Enclosure with 75W PSU ENS-PANL-2101 5
(2) Entro Stars 24x20x4.5 Enclosure (2) 75W PSU ENS-PANL-4102 1
Boost Buck Converter, DC 5.5-30V ZK-DP60 7
LiFePO4 Lithium Battery 12V 25AH YD1225 7
Industrial 8-Port Wall-mount Managed Switch with LCD touch screen WGS-5225-8P2SV 2
Device Enclosure E2-BOXED 2
SCIF Computer ACS-10116 1
J60 Lithium UPS J60-350 2
APC Back-UPS Pro, 700VA/420W BR700G 1
120VAC, 20AMP, Dedicated Circuit, Parallel Mount, SPD Type 1, Surge
Protector
DTK-120HW 2
AC 120V NEMA 5-15R Single Receptacle Outlet Power Strip Module D-1559T 2
Mini GBIC LX Module-20KM MGB-TLX 2
TAPE DBL SIDED BLACK 1 ½” x 5YDS 3M 1
RIOX PCB Assembly ACB-07637-1 1
130W 54V AC-to-DC Desktop Power Adapter PWR-130-54 2
Miscellaneous Install Material (rigid conduit, cabling, etc.) Misc.
File details come from the government source that posted it. Updated .