SP4702-20-Q-0016.pdf

PDF 827 KB Posted

Attached to
Medical First Responder Training Federal contract opportunity
Solicitation number
SP4702-20-Q-0016
Issued by
Defense Logistics Agency

View the file

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

PR: 83776446

FR: 200102903

Ledger: 61002520 Cost Center: 8000025 Request for Quote: SP4702-20-Q-0016 Description: Medical First Responder Training Period of Performance: Base year with four option years.

Location: Hart-Dole-Inouye Federal Center (HDIFC) located in Battle Creek, MI Contract Lines: 0001 Base Year, 1001 Option Year 1, 2001, Option Year 3001, & 4001 Option Year 4.

Other Than Full and Open Competition, Firm-Fixed-Price, and Commercial Acquisition Non-Personal Service FOB Origin with Inspection and Acceptance at Destination (WAWF Acceptance DoDAAC#

TBD)

FAR 12.6 "Streamlined Procedures for Evaluation and Solicitation for Commercial Items", FAR 13 "Simplified Acquisition Procedures” and FAR 37 "Service Contracting" regulations and procedures will be utilized.

This is a combined synopsis/solicitation for commercial items prepared in accordance with the format in Subpart 12.6, as supplemented with additional information included in this notice. This announcement constitutes the only solicitation; quotes are being requested and a written solicitation will not be issued. This solicitation, SP4702-20-Q-0016, is being issued as a Request for Quote (RFQ). This solicitation document and incorporated provisions and clauses are those in effect through Federal Acquisition Circular (FAC) 2005-95. Solicitation opening date is July 30, 2020 and closing date is August 13, 2020 1:00s p.m. (Eastern Time). This procedure combines the synopsis required by FAR 5.203 and the issuance of the solicitation into a single document.

The NAICS code is 611710 and the business size standard is $16.5M. The following commercial services are requested in this solicitation:

Performance Work Statement, see attachment # 1

Contract Line Item Numbers (CLIN’s), and quantities are as follows:

Section B, attachment #2:

CLIN Begin End Base Year 0001 October 1, 2020 September 30, 2021 Option Year 1 1001 October 1, 2021 September 30, 2022 Option Year 2 2001 October 1, 2022 September 30, 2023 Option Year 3 3001 October 1, 2023 September 30, 2024 Option Year 4 4001 October 1, 2024 September 30, 2025

The clauses listed in Attachment 3 are incorporated into this solicitation by reference or in full text as provided.

It is anticipated that a firm-fixed price purchase order will be awarded for the requested non-personal service as a result of this combined synopsis/solicitation. Award will be based on Technical Service Capabilities, Technical Qualifications of Proposed Staffing and Past Performance, See Attachment 4 for Secitons L and M. Single award is expected to be made for this acquisition.

System of Award Management Requirement

No award will be made to a Contractor not registered in the System of Award Management (SAM). In addition, the Contractor's Representations and Certification must be listed in the SAM database. Reference https://www.acquisition.gov or https://www.sam.gov/portal/public/SAM/.

Note: There is no fee to register and use this site.

During the contract, the Contractor must always have an active status in SAM during the life of this contract. Invoices will be paid using the financial information provided in the Contractor's SAM profile. Failure to keep an active status may result in payment delays and other administration delays.

Standard Form (SF) - 1449 (pages 1 and 2), see attachment # 4.

Quotes are due by 1:00 p.m. (EST) time on August 13, 2020.

Electronic proposals must be submitted via e-mail to Kristin Schoeck at kristin.schoeck@dla.mil.

Facsimile proposals will not be accepted. Questions regarding this solicitation may be directed to Kristin Schoeck at kristin.schoeck@dla.mil no later than Monday, August 10, 2020 before noon.

Attachments:

#1 - Performance Work Statement #2 - Section B #3 - Provisions and Clauses, Selection Criteria

Bid MUST be good for 45 calendar days after close of Buy.

Please complete provision 52.212-3, Offeror Representations and Certifications- Commercial Items; OR indicate that your company's representation's and certifications are current and available via Sam.gov.

Questions shall be addresses to:

Government Contract Officer Kristin Schoeck DLA Land and Maritime

DCSO-C

3990 E. Broad St., Bldg 20 Columbus, OH 43218 kristin.schoeck@dla.mil, Phone: 614-692-0489

PLEASE PROVIDE THE FOLLOWING INFORMATION SO YOUR COMPANY CAN BE

ENTERED INTO OUR COMPUTER SYSTEM:

CAGE Code (Commercial & Government Entity No.) _______________ (SF 1449, 1ST PAGE, BLOCK #17a).

DUNS (Dun & Bradstreet) No. _________________________ (SF 1449, 1ST PAGE, BLOCK #17a)

SAM (System for Award Management): Yes or No (circle one).

TAX ID NO. (TIN):_____________________________.

Business size (in accordance with Federal Government Standards)

Small ____ Large ____Women-Owned____ Disadvantaged _____ Other_____

Attachment 1 Medical First Responder Training

Performance Work Statement (PWS)

A. Objectives

1. In the interest of creating an agile and flexible Medical Response Team (MRT) medical first responder (MFR) program for the Hart Dole Inouye Federal Center (HDIFC) and meeting the requirements of the Michigan Department of Public Health Emergency Medical Services (EMS) Division and in keeping with the highest of standards within Defense Logistics Agency (DLA) the following are requirements are submitted.

Provide MFR training to meet the State of Michigan licensure requirements according to Michigan Department of Public Health EMS Division. This training must be taught by a State of Michigan licensed EM Instructor per the Michigan Department of Public Health EMS Division regulations.

The MFR Course is designed to provide training for the student to obtain licensure with the Michigan Department of Public Health as a medical first responder. This continuation of state licensure will ensure the well-being of the employees at the HDIFC by providing assistance with-in the facility in the event of an emergency whether it is a medical, natural or manmade disaster.

This course is for MRT members that have completed six months of shadowing as a MFR volunteer.

Course will include CPR, AED, bleeding control, airway management, splinting, extrications, medical emergencies 8 hours a day one day per week for 12 weeks.

B. Scope

1. The instructor shall successfully deliver the EMT 110 Medical First Responder Training

2. The instructor shall successfully instruct a maximum of 12 students per course at the HDIFC in

Battle Creek.

3. At least two weeks prior to the actual course the instructor shall meet (teleconference) with key employees (see A.8) of DLA Finance, Installation Management at Battle Creek to get a detailed understanding of the operations as they relate to Medical First Responder course. This shall be in sufficient time to develop the course materials and coordinate with DLA Installation Management @ Battle Creek.

C. Specific Tasks

1. The activities associated with this project shall be categorized into the following tasks:

a. The instructor shall successfully deliver 1 (one) day per week for 12 weeks the EMT 110

Medical First Responder Training course MFR Training.

b. At a minimum the course shall provide: the comprehensive skills and in-depth knowledge needed by the attendees to pass the National Certification for MFR’s.

c. At a minimum each topic shall provide the following topics/objectives:

i. Health Care Provider CPR

ii. Airway

1) Breathing and Ventilation

2) Airway Care and Maintenance

iii. Circulation

1) Circulation

2) Automated External Defibrillation

iv. Patient Assessment

1) Scene Size-up

2) Introduction to Patient Assessment and Vital Signs

3) Patent Assessment

4) Communication and Documentation

v. Illness and Injury

1) Cardiac and Respiratory Emergencies

2) Medical Emergencies

3) Environmental Emergencies

4) Psychological Emergencies and Crisis Intervention

5) Bleeding and Shock

6) Soft-Tissue Injuries

7) Injuries to Chest, Abdomen, and Genitalia

8) Injuries to the Head, Face, and Neck

9) Musculoskeletal Injuries

vi. Childbirth and Children

1) Childbirth

2) Infants and Children

vii. Geriatric Considerations

1) Geriatric Patients

viii. EMS Operations

1) EMS Operations

2) Hazardous Material Incidents and Incident Command

3) Multiple-Casualty Incidents and Patient Extrication

4) Water Emergences

5) Vehicle Stabilization and Patient Extrication

6) Special Rescue

7) First Response to Terrorist Incidents

D. Key Personnel Skill Qualifications

1. Offeror shall be accredited from a higher learning institute, Accredited State of Michigan license

EMS instructor/coordinator. Provide with their proposal resume(s) of the instructor(s) to perform this training that demonstrates having obtained formal instructor or facilitator training, and specific and detailed knowledge of and proficiency in EMS training, performance in the field and the office setting, as well as the ability to communicated effectively to ensure that all facets of the training are absorbed by the attendees, and the flexibility of adjusting the training to accommodate special needs of attendees.

E. Course Materials

1. The vendor shall provide all printed course materials, rosters, software, evaluation/course feedback forms and Vendor Visual aids necessary to perform the class, course completion certificates, and any other training supplies necessary to successfully deliver the course.

F. Government Furnished Materials

1. The government will provide classroom space and set-up, logistics management, hardware and any supplemental software licenses as may be required.

G. Deliverables

1. The instructor shall provide the DLA Finance, Log Info Svc Point of Contact a copy of the roster, course evaluations and any course feedback as appropriate within five ( 5) business ,days after each course is completed.

H. Point of Contact: Adam Beam

Customer Point of Contact:

Adam Beam Installation Management DM-FBS Security Services Emergency Management Adam.Beam@dla.mil Comm (269)961-7476

The Government Contracting Officer: Kristin Schoeck DLA Contracting Services Office, Columbus (DCSO-C) 3990 E. Broad St., Bldg 20 Columbus, OH 43213 Kristin.Schoeck@dla.mil ; Phone: 614-692-0489

I. Period of Performance

1. One course shall be delivered during each period of performance with course start dates at the end of May or beginning of June. The following period of performance periods are open for this class:

2.

Begin End Base Year October 1, 2020 September 30, 2021 Option Year 1 October 1, 2021 September 30, 2022 Option Year 2 October 1, 2022 September 30, 2023 Option Year 3 October 1, 2023 September 30, 2024 Option Year 4 October 1, 2024 September 30, 2025

3. Class shall start at 9:00 a.m. and end at 16:00. No work shall be performed during weekend of federal holidays. Government will not be paying overtime to the contractor. Work hours are mailto:Adam.Beam@dla.mil subject to change after award per customer request.

4. If the above period will not work for the contractor, the contractor shall provide an alternative training period or periods; however, the Government reserves the right to reject alternative date/offer if facilities are not available or if the date is not considered mutually acceptable.

J. Technical Documentation

1. Offeror shall submit a course outline which identifies how the teaching method will be equal to the specifications listed in Sections C and D above.

K. Federally Observed Holidays

1. The following legal holidays are observed by this agency:

Monday, January 1 New Year’s Day Third Monday in January Birthday of Martin Luther King, Jr.

Third Monday in February President’s Day Last Monday in May Memorial Day July 4 Independence Day First Monday in September Labor Day Second Monday in October Columbus Day November 11 Veterans Day Fourth Thursday in November Thanksgiving Day December 25 Christmas Day

L. Section 508 Compliance

1. Section 508 of the Rehabilitation Act requires Federal agencies to make their electronic and information technology accessible to people with disabilities. This applies to all Federal agencies when they develop, procure, maintain, or use electronic and information technology. Any/all electronic and information technology procured through this effort must meet the applicable accessibility standards at 36 CFR 1194. 36 CFR 1194 implements Section 508 of the Rehabilitation Act of 1973, as amended, and is viewable at http://www.section508.gov

M. Security Requirements:

1. Contractor and all associated sub-contractor’s employees shall comply with applicable installation, facility and area commander installation/facility access and local security policies and procedures (provided by government representative). The contractor shall also provide all information required for background checks to meet installation access requirements to be accomplished by Security Office. Contractor workforce shall comply with all personal identity verification requirements as directed by DOD, HQ DLA and/or local policy. Should the Force Protection Condition (FPCON) change, the Government may require changes in contractor security matters or processes.

N. Invoicing:

1. Payment of invoices will be accomplished by payment through the Defense Finance and

Accounting Service. Invoices will be submitted to the Wide Area Workflow system in accordance with DFARS 252.232-7003 Electronic Submission of Payment Requests and Receiving Reports http://www.section508.gov/ and DFARS 252.232-7006 Wide Area Workflow Payment Instructions within 10 workdays after the conclusion of work performed. Invoices shall be submitted through Wide Area Workflow (WAWF), See DFARS Clause 252.232-7006 Wide Area Workflow Payment Instructions for detailed instructions on how to submit invoices.

O. Common Access Card:

1. Common Access Card (CAC) not required. Prior to gaining access to any DLA facility, contractor personnel must be vetted through the local security office. Due to DoD security requirements, foreign nationals and illegal aliens will not be permitted access to any DLA facility.

Individuals with outstanding warrants or certain convictions also will be denied access.

Contractor personnel must ensure they have the appropriate identification required to access DLA facilities. Contractor personnel entering a DLA facility should anticipate their vehicle will undergo a security check by DLA Security, and should ensure that no drugs, alcohol, or weapons of any kind are found within the vehicle. It is the contractor’s responsibility to ensure the personnel performing under this contract can and will meet these requirements for accessing DLA facilities. Names of contractor personnel will be provided to the local POC for vetting purposes no less than one week prior to the class start date.

P. C05 Changes to Key Personnel (OCT 2016).

1. Certain skilled, experienced, professional and/or technical personnel are essential for successful accomplishment of the work to be performed under this contract. These are defined as "key personnel" and are those persons whose resumes are submitted as part of the technical/ business proposal for evaluation. The contractor shall use key personnel as identified in its proposal during the performance of this contract and will request contracting officer approval prior to any changes. Requests for approval of any changes shall be in writing with a detailed explanation of the circumstances necessitating the change. The request must contain a complete resume for the new key personnel and any other pertinent information, such as degrees, certifications, and work history. New key personnel must have qualifications that are equal to or higher than those being replaced. The contracting officer will evaluate the request and notify the contractor whether the requested change is acceptable to the Government.

Attachment 2

SECTION B

CLIN Material Code QUANTITY UNIT OF

ISSUE

UNIT

PRICE

TOTAL

AMOUNT

U009- V00007702 “Educational Service”

1.00

JB

1001 U009- V00007702

2001 U009- V00007702

3001 U009- V00007702

4001 U009- V00007702

TOTAL =

Note: Contractor must complete the following two columns; unit price and total amount.

Required Delivery is once annually per period of performance.

ASSISTANCE IN SUBMITTING DOCUMENTS/INVOICES INTO THE WIDE AREA

WORKFLOW (WAWF)

If you need instruction on how to submit an invoice to the Government in WAWF, follow the below instructions. It is not necessary to log into WAWF to access the training.

1. Click on the Help/Training folder located on the top right hand corner WAWF home page.

https://wawf.eb.mil/xhtml/unauth/home/login.xhtml#

2. Go to Training

3. Click on Web based Training

4. Click on iRAPT

5. Go to Roles and click on vendor

6. Click Vendor creating documents in iRAPT

7. Under Document, Scroll down through the documents list and selected the document you wish to learn about. In this case the document you should select is The 2 in 1 (Services Only). You find both a video and step by step instructions on how to complete any the form and be able to submit your invoice into WAWF.

After reviewing this information and you are still having problems, you can call the Defense Finance and Accounting Services (DFAS) Help Desk at 1-800-756-4571 Prompt 2. Their hours of operation are between 7:30 AM to 4:30 PM; Monday to Friday Eastern Standard Time.

Assistance may also be available to assist in the submission of the invoice by contacting the Procurement Technical Assistance Center (PTAC) office located in your State. There is an office for your county.

Their website for further information is: http://www.dla.mil/HQ/SmallBusiness/PTAC.aspx#DDL_Lines http://www.dla.mil/HQ/SmallBusiness/PTAC.aspx#DDL_Lines

Attachment 3 Clauses

SECTION D - PACKAGING AND MARKING

NOT APPLICABLE

SECTION E - INSPECTION AND ACCEPTANCE

52.246-04, Inspection of Services - Fixed Price (AUG 1996) FAR 252.246-7000, Material Inspection and Receiving Report (MAR 2008) DFARS

SECTION F - DELIVERIES OR PERFORMANCE

52.242-15, Stop Order (AUG 1989) FAR 52.242-17, Government Delay of Work (APR 1984) FAR 52.247-34, F.O.B. Destination (NOV 1991) FAR

SECTION G

252.323-7006 Wide Area Workflow Payment Instructions (DEC 2018) DFARS

(a) Definitions. As used in this clause— “Department of Defense Activity Address Code (DoDAAC)” is a six position code that uniquely identifies a unit, activity, or organization.

“Document type” means the type of payment request or receiving report available for creation in Wide Area WorkFlow (WAWF).

“Local processing office (LPO)” is the office responsible for payment certification when payment certification is done external to the entitlement system.

“Payment request” and “receiving report” are defined in the clause at 252.232-7003, Electronic Submission of Payment Requests and Receiving Reports.

(b) Electronic invoicing. The WAWF system provides the method to electronically process vendor payment requests and receiving reports, as authorized by Defense Federal Acquisition Regulation Supplement (DFARS) 252.232-7003, Electronic Submission of Payment Requests and Receiving Reports.

(c) WAWF access. To access WAWF, the Contractor shall—

(1) Have a designated electronic business point of contact in the System for Award Management at https://www.sam.gov; and

2) Be registered to use WAWF at https://wawf.eb.mil/ following the step-by-step procedures for self-registration available at this web site.

(d) WAWF training. The Contractor should follow the training instructions of the WAWF Web- Based Training Course and use the Practice Training Site before submitting payment requests through WAWF. Both can be accessed by selecting the “Web Based Training” link on the WAWF home page at https://wawf.eb.mil/

(e) WAWF methods of document submission. Document submissions may be via web entry, Electronic Data Interchange, or File Transfer Protocol.

(f) WAWF payment instructions. The Contractor shall use the following information when submitting payment requests and receiving reports in WAWF for this contract or task or delivery order:

(1) Document type. The Contractor shall submit payment requests using the following document type(s): 2 in 1 Invoice

(2) Fast Pay requests are only permitted when Federal Acquisition Regulation (FAR) 52.213-1 is included in the contract. (

(3) Document routing. The Contractor shall use the information in the Routing Data Table below only to fill in applicable fields in WAWF when creating payment requests and receiving reports in the system.

Routing Data Table*

Field Name in WAWF Data to be entered in WAWF Pay Official DoDAAC SL4701 Issue By DoDAAC SP4702 Admin DoDAAC SP4702 Inspect By DoDAAC TBD Ship To Code N/A Ship From Code N/A Mark For Code N/A Service Approver (DoDAAC) N/A Service Acceptor (DoDAAC) TBD Accept at Other DoDAAC N/A LPO DoDAAC N/A DCAA Auditor DoDAAC N/A Other DoDAAC(s) N/A

(4) Payment request. The Contractor shall ensure a payment request includes documentation appropriate to the type of payment request in accordance with the payment clause, contract financing clause, or Federal Acquisition Regulation 52.216-7, Allowable Cost and Payment, as applicable.

(5) Receiving report. The Contractor shall ensure a receiving report meets the requirements of DFARS Appendix F.

(g) WAWF point of contact.

(1) The Contractor may obtain clarification regarding invoicing in WAWF from the following contracting activity’s WAWF point of contacts:

TBD

(2) Contact the WAWF helpdesk at 866-618-5988, if assistance is needed

SECTION I

C05, Changes to Key Personnel.

52.203-17 Contractor Employee Whistleblower Rights and Requirements to Inform to Employees of Whistleblower Rights (APR 2014) FAR

52.203-18, Prohibition on Contracting with Entities that Require Certain Internal Confidential Agreements or Statements-Representation (JAN 2017) FAR

252.201-7000, Contracting Officer's Representative (DEC 1991) DFARS

252.203-7000, Requirements Relating to Compensation of Former DoD Officials (SEP 2011)

DFARS

252.203-7002, Requirement to Inform Employees of Whistleblower Rights (SEP 2013) DFARS

252.203-7005, Representation Relating to Compensation of Former DoD Officials (NOV 2011)

52.204-7, System for Award Management (OCT 2016) FAR

52.204-16, Commercial and Government Entity Code Reporting (JUL 2015) FAR

52.204-18, Commercial and Government Entity Code Maintenance (JUL 2015) FAR

52.204-19, Incorporation by Reference of Representations and Certifications (DEC 2014) FAR

52.204-23, Prohibition on Contracting for Hardware, Software, and Services Developed or Provided by Kaspersky Lab or Other Covered (Jul 2018) FAR

52.204– 24, Representation Regarding Certain Telecommunications and Video Surveillance Services or Equipment (DEC 2019) FAR

52.204–25, Prohibition on Contracting for Certain Telecommunications and Video Surveillance Services or Equipment (DEC 2019) FAR

52.204-26, Covered Telecommunications Equipment or Services (DEC 2019) FAR

252.204-7003, Control of Government Personnel Work Product (APR 1992) DFARS

252.204-7004 Alternate A, System For Award Management (FEB 2014) DFARS

252.204-7008 Compliance With Safeguarding Covered Defense Information Controls (Oct 2016)

DFARS

(a) Definitions. As used in this provision— “Controlled technical information,” “covered contractor information system,” and “covered defense information” are defined in clause 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting.

(b) The security requirements required by contract clause 252.204-7012, Covered Defense Information and Cyber Incident Reporting, shall be implemented for all covered defense information on all covered contractor information systems that support the performance of this contract.

(c) For covered contractor information systems that are not part of an information technology (IT) service or system operated on behalf of the Government (see 252.204-7012(b)(1)(ii))—

(1) By submission of this offer, the Offeror represents that it will implement the security requirements specified by National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171, “Protecting Controlled Unclassified Information in Nonfederal Information Systems and Organizations” (see http://dx.doi.org/10.6028/NIST.SP.800-171), not later than December 31, 2017.

(2)(i) If the Offeror proposes to vary from any of the security requirements specified by NIST SP 800-171 that is in effect at the time the solicitation is issued or as authorized by the Contracting Officer, the Offeror shall submit to the Contracting Officer, for consideration by the DoD Chief Information Officer (CIO), a written explanation of—

(A) Why a particular security requirement is not applicable; or

(B) How an alternative but equally effective, security measure is used to compensate for the inability to satisfy a particular requirement and achieve equivalent protection.

(ii) An authorized representative of the DoD CIO will adjudicate offeror requests to vary from NIST SP 800-171 requirements in writing prior to contract award. Any accepted variance from NIST SP 800-171 shall be incorporated into the resulting contract.

(End of provision)

252.204-7009, Limitations on the Use or Disclosure of Third-Party Contractor Reported Cyber Incident (OCT 2016) DFARS

(a) Definitions. As used in this clause— “Compromise” means disclosure of information to unauthorized persons, or a violation of the security policy of a system, in which unauthorized intentional or unintentional disclosure, modification, destruction, or loss of an object, or the copying of information to unauthorized media may have occurred.

“Controlled technical information” means technical information with military or space application that is subject to controls on the access, use, reproduction, modification, performance, display, release, disclosure, or dissemination. Controlled technical information would meet the criteria, if disseminated, for distribution statements B through F using the criteria set forth in DoD Instruction 5230.24, Distribution Statements on Technical Documents. The term does not include information that is lawfully publicly available without restrictions.

“Covered defense information” means unclassified controlled technical information or other information (as described in the Controlled Unclassified Information (CUI) Registry at http://www.archives.gov/cui/registry/category-list.html) that requires safeguarding or dissemination controls pursuant to and consistent with law, regulations, and Government wide policies, and is—

(1) Marked or otherwise identified in the contract, task order, or delivery order and provided to the contractor by or on behalf of DoD in support of the performance of the contract; or

(2) Collected, developed, received, transmitted, used, or stored by or on behalf of the contractor in support of the performance of the contract.

“Cyber incident” means actions taken through the use of computer networks that result in a compromise or an actual or potentially adverse effect on an information system and/or the information residing therein.

“Information system” means a discrete set of information resources organized for the collection, processing, maintenance, use, sharing, dissemination, or disposition of information.

“Media” means physical devices or writing surfaces including, but is not limited to, magnetic tapes, optical disks, magnetic disks, large-scale integration memory chips, and printouts onto which covered defense information is recorded, stored, or printed within a covered contractor information system.

“Technical information” means technical data or computer software, as those terms are defined in the clause at DFARS 252.227-7013, Rights in Technical Data-Noncommercial Items, regardless of whether or not the clause is incorporated in this solicitation or contract. Examples of technical information include research and engineering data, engineering drawings, and associated lists, specifications, standards, process sheets, manuals, technical reports, technical orders, catalog-item identifications, data sets, studies and analyses and related information, and computer software executable code and source code.

(b) Restrictions. The Contractor agrees that the following conditions apply to any information it receives http://dx.doi.org/10.6028/NIST.SP.800-171) http://www.archives.gov/cui/registry/category-list.html http://www.acq.osd.mil/dpap/dars/dfars/html/current/252227.htm#252.227-7013 or creates in the performance of this contract that is information obtained from a third-party’s reporting of a cyber-incident pursuant to DFARS clause 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting (or derived from such information obtained under that clause):

(1) The Contractor shall access and use the information only for the purpose of furnishing advice or technical assistance directly to the Government in support of the Government’s activities related to clause 252.204-7012, and shall not be used for any other purpose.

(2) The Contractor shall protect the information against unauthorized release or disclosure.

(3) The Contractor shall ensure that its employees are subject to use and non-disclosure obligations consistent with this clause prior to the employees being provided access to or use of the information.

(4) The third-party contractor that reported the cyber incident is a third-party beneficiary of the non-disclosure agreement between the Government and Contractor, as required by paragraph (b)(3) of this clause.

(5) A breach of these obligations or restrictions may subject the Contractor to—

(i) Criminal, civil, administrative, and contractual actions in law and equity for penalties, damages, and other appropriate remedies by the United States; and

(ii) Civil actions for damages and other appropriate remedies by the third party that reported the cyber incident, as a third party beneficiary of this clause.

(c) Subcontracts. The Contractor shall include this clause, including this paragraph (c), in subcontracts, or similar contractual instruments, for services that include support for the Government’s activities related to safeguarding covered defense information and cyber incident reporting, including subcontracts for commercial items, without alteration, except to identify the parties.

(End of clause)

252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting (OCT

2016) DFARS

(a) Definitions. As used in this clause— “Adequate security” means protective measures that are commensurate with the consequences and probability of loss, misuse, or unauthorized access to, or modification of information.

“Compromise” means disclosure of information to unauthorized persons, or a violation of the security policy of a system, in which unauthorized intentional or unintentional disclosure, modification, destruction, or loss of an object, or the copying of information to unauthorized media may have occurred.

“Contractor attributional/proprietary information” means information that identifies the contractor(s), whether directly or indirectly, by the grouping of information that can be traced back to the contractor(s) (e.g., program description, facility locations), personally identifiable information, as well as trade secrets, commercial or financial information, or other commercially sensitive information that is not customarily shared outside of the company.

“Contractor information system” means an information system belonging to, or operated by or for, the Contractor.

“Controlled technical information” means technical information with military or space application that is subject to controls on the access, use, reproduction, modification, performance, display, release, disclosure, or dissemination. Controlled technical information would meet the criteria, if disseminated, for distribution statements B through F using the criteria set forth in DoD Instruction 5230.24, Distribution Statements on Technical Documents. The term does not include information that is lawfully publicly available without restrictions.

“Covered contractor information system” means an information system that is owned, or operated by or for, a contractor and that processes, stores, or transmits covered defense information.

“Covered defense information” means unclassified information that—

(i) Is— http://www.acq.osd.mil/dpap/dars/dfars/html/current/252204.htm#252.204-7012 http://www.acq.osd.mil/dpap/dars/dfars/html/current/252204.htm#252.204-7012

(A) Provided to the contractor by or on behalf of DoD in connection with the performance of the contract;

or

(B) Collected, developed, received, transmitted, used, or stored by or on behalf of the contractor in support of the performance of the contract; and

(ii) Falls in any of the following categories:

(A) Controlled technical information.

(B) Critical information (operations security). Specific facts identified through the Operations Security process about friendly intentions, capabilities, and activities vitally needed by adversaries for them to plan and act effectively so as to guarantee failure or unacceptable consequences for friendly mission accomplishment (part of Operations Security process).

(C) Export control. Unclassified information concerning certain items, commodities, technology, software, or other information whose export could reasonably be expected to adversely affect the United States national security and nonproliferation objectives. To include dual use items; items identified in export administration regulations, international traffic in arms regulations and munitions list; license applications; and sensitive nuclear technology information.

(D) Any other information, marked or otherwise identified in the contract, that requires safeguarding or dissemination controls pursuant to and consistent with law, regulations, and Governmentwide policies (e.g.,privacy, proprietary business information).

“Cyber incident” means actions taken through the use of computer networks that result in a compromise or an actual or potentially adverse effect on an information system and/or the information residing therein.

“Forensic analysis” means the practice of gathering, retaining, and analyzing computer-related data for investigative purposes in a manner that maintains the integrity of the data.

“Malicious software” means computer software or firmware intended to perform an unauthorized process that will have adverse impact on the confidentiality, integrity, or availability of an information system.

This definition includes a virus, worm, Trojan horse, or other code-based entity that infects a host, as well as spyware and some forms of adware.

“Media” means physical devices or writing surfaces including, but is not limited to, magnetic tapes, optical disks, magnetic disks, large-scale integration memory chips, and printouts onto which information is recorded, stored, or printed within an information system.

‘‘Operationally critical support’’ means supplies or services designated by the Government as critical for airlift, sealift, intermodal transportation services, or logistical support that is essential to the mobilization, deployment, or sustainment of the Armed Forces in a contingency operation.

“Rapid(ly) report(ing)” means within 72 hours of discovery of any cyber incident.

“Technical information” means technical data or computer software, as those terms are defined in the clause at DFARS 252.227-7013, Rights in Technical Data-Non Commercial Items, regardless of whether or not the clause is incorporated in this solicitation or contract. Examples of technical information include research and engineering data, engineering drawings, and associated lists, specifications, standards, process sheets, manuals, technical reports, technical orders, catalog-item identifications, data sets, studies and analyses and related information, and computer software executable code and source code.

(b) Adequate security. The Contractor shall provide adequate security for all covered defense information on all covered contractor information systems that support the performance of work under this contract.

To provide adequate security, the Contractor shall—

(1) Implement information systems security protections on all covered contractor information systems including, at a minimum—

(i) For covered contractor information systems that are part of an Information Technology (IT) service or system operated on behalf of the Government—

(A) Cloud computing services shall be subject to the security requirements specified in the clause 252.239-7010, Cloud Computing Services, of this contract; and

(B) Any other such IT service or system (i.e., other than cloud computing) shall be subject to the security requirements specified elsewhere in this contract; or

(ii) For covered contractor information systems that are not part of an IT service or system operated on behalf of the Government and therefore are not subject to the security requirement specified at paragraph (b)(1)(i) of this clause—

(A) The security requirements in National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171, “Protecting Controlled Unclassified Information in Nonfederal Information Systems and Organizations,” http://dx.doi.org/10.6028/NIST.SP.800-171 that is in effect at the time the solicitation is issued or as authorized by the Contracting Officer, as soon as practical, but not later than December 31, 2017. The Contractor shall notify the DoD CIO, via email at osd.dibcsia@mail.mil, within 30 days of contract award, of any security requirements specified by NIST SP 800-171 not implemented at the time of contract award; or

(B) Alternative but equally effective security measures used to compensate for the inability to satisfy a particular requirement and achieve equivalent protection accepted in writing by an authorized representative of the DoD CIO; and

(2) Apply other information systems security measures when the Contractor easonably determines that information systems security measures, in addition to those identified in paragraph (b)(1) of this clause, may be required to provide adequate security in a dynamic environment based on an assessed risk or vulnerability

(c) Cyber incident reporting requirement

(1) When the Contractor discovers a cyber incident that affects a covered contractor information system or the covered defense information residing therein, or that affects the contractor’s ability to perform the requirements of the contract that are designated as operationally critical support, the Contractor shall—

(i) Conduct a review for evidence of compromise of covered defense information, including, but not limited to, identifying compromised computers, servers, specific data, and user accounts. This review shall also include analyzing covered contractor information system(s) that were part of the cyber incident, as well as other information systems on the Contractor’s network(s), that may have been accessed as a result of the incident in order to identify compromised covered defense information, or that affect the Contractor’s ability to provide operationally critical support; and

(ii) Rapidly report cyber incidents to DoD at http://dibnet.dod.mil.

(2) Cyber incident report. The cyber incident report shall be treated as information created by or for DoD and shall include, at a minimum, the required elements at http://dibnet.dod.mil.

(3) Medium assurance certificate requirement. In order to report cyber incidents in accordance with this clause, the Contractor or subcontractor shall have or acquire a DoD-approved medium assurance certificate to report cyber incidents. For information on obtaining a DoD-approved medium assurance certificate, see http://iase.disa.mil/pki/eca/Pages/index.aspx.

(d) Malicious software. The Contractor or subcontractors that discover and isolate malicious software in connection with a reported cyber incident shall submit the malicious software in accordance with instructions provided by the Contracting Officer.

(e) Media preservation and protection. When a Contractor discovers a cyber incident has occurred, the Contractor shall preserve and protect images of all known affected information systems identified in paragraph (c)(1)(i) of this clause and all relevant monitoring/packet capture data for at least 90 days from the submission of the cyber incident report to allow DoD to request the media or decline interest.

(f) Access to additional information or equipment necessary for forensic analysis. Upon request by DoD, the Contractor shall provide DoD with access to additional information or equipment that is necessary to conduct a forensic analysis.

http://dx.doi.org/10.6028/NIST.SP.800-171 mailto:osd.dibcsia@mail.mil http://dibnet.dod.mil/ http://dibnet.dod.mil/ http://iase.disa.mil/pki/eca/Pages/index.aspx

(g) Cyber incident damage assessment activities. If DoD elects to conduct a damage assessment, the Contracting Officer will request that the Contractor provide all of the damage assessment information gathered in accordance with paragraph (e) of this clause.

(h) DoD safeguarding and use of contractor attributional/proprietary information. The Government shall protect against the unauthorized use or release of information obtained from the contractor (or derived from information obtained from the contractor) under this clause that includes contractor attributional/proprietary information, including such information submitted in accordance with paragraph (c). To the maximum extent practicable, the Contractor shall identify and mark attributional/proprietary information. In making an authorized release of such information, the Government will implement appropriate procedures to minimize the contractor attributional/proprietary information that is included in such authorized release, seeking to include only that information that is necessary for the authorized purpose(s) for which the information is being released.

(i) Use and release of contractor attributional/proprietary information not created by or for DoD.

Information that is obtained from the contractor (or derived from information obtained from the contractor) under this clause that is not created by or for DoD is authorized to be released outside of DoD—

(1) To entities with missions that may be affected by such information;

(2) To entities that may be called upon to assist in the diagnosis, detection, or mitigation of cyber incidents;

(3) To Government entities that conduct counterintelligence or law enforcement investigations;

(4) For national security purposes, including cyber situational awareness and defense purposes (including with Defense Industrial Base (DIB) participants in the program at 32 CFR part 236); or

(5) To a support services contractor (“recipient”) that is directly supporting Government activities under a contract that includes the clause at 252.204-7009, Limitations on the Use or Disclosure of Third-Party Contractor Reported Cyber Incident Information.

(j) Use and release of contractor attributional/proprietary information created by or for DoD.

Information that is obtained from the contractor (or derived from information obtained from the contractor) under this clause that is created by or for DoD (including the information submitted pursuant to paragraph (c) of this clause) is authorized to be used and released outside of DoD for purposes and activities authorized by paragraph (i) of this clause, and for any other lawful Government purpose or activity, subject to all applicable statutory, regulatory, and policy based restrictions on the Government’s use and release of such information.

(k) The Contractor shall conduct activities under this clause in accordance with applicable laws and regulations on the interception, monitoring, access, use, and disclosure of electronic communications and data.

(l) Other safeguarding or reporting requirements. The safeguarding and cyber incident reporting required by this clause in no way abrogates the Contractor’s responsibility for other safeguarding or cyber incident reporting pertaining to its unclassified information systems as required by other applicable clauses of this contract, or as a result of other applicable U.S. Government statutory or regulatory requirements.

(m) Subcontracts. The Contractor shall—

(1) Include this clause, including this paragraph (m), in subcontracts, or similar contractual instruments, for operationally critical support, or for which subcontract performance will involve a covered contractor information system, including subcontracts for commercial items, without alteration, except to identify the parties; and

(2) When this clause is included in a subcontract, require subcontractors to rapidly report cyber incidents directly to DoD at http://dibnet.dod.mil and the prime Contractor. This includes providing the incident report number, automatically assigned by DoD, to the prime Contractor (or next higher-tier subcontractor) as soon as practicable.

(End of provision) http://dibnet.dod.mil/

252.204-7015, Notice of Authorized Disclosure of Information for Litigation Support (MAY 2016)

52.212-3 Offeror Representations And Certifications - Commercial Items (DEC 2019) FAR The Offeror shall complete only paragraph (b) of this provision if the Offeror has completed the annual representations and certification electronically in the System for Award Management (SAM) accessed through https://www.sam.gov. If the Offeror has not completed the annual representations and certifications electronically, the Offeror shall complete only paragraphs (c) through (v)) of this provision.

(a) Definitions. As used in this provision—

“Covered telecommunications equipment or services” has the meaning provided in the clause 52.204-25, Prohibition on Contracting for Certain Telecommunications and Video Surveillance Services or Equipment.

“Economically disadvantaged women-owned small business (EDWOSB) concern” means a small business concern that is at least 51 percent directly and unconditionally owned by, and the management and daily business operations of which are controlled by, one or more women who are citizens of the United States and who are economically disadvantaged in accordance with 13 CFR part 127. It automatically qualifies as a women-owned small business eligible under the WOSB Program.

“Forced or indentured child labor” means all work or service—

(1) Exacted from any person under the age of 18 under the menace of any penalty for its nonperformance and for which the worker does not offer himself voluntarily; or

(2) Performed by any person under the age of 18 pursuant to a contract the enforcement of which can be accomplished by process or penalties.

“Highest-level owner” means the entity that owns or controls an immediate owner of the offeror, or that owns or controls one or more entities that control an immediate owner of the offeror. No entity owns or exercises control of the highest level owner.

“Immediate owner” means an entity, other than the offeror, that has direct control of the offeror.

Indicators of control include, but are not limited to, one or more of the following: ownership or interlocking management, identity of interests among family members, shared facilities and equipment, and the common use of employees.

“Inverted domestic corporation”, means a foreign incorporated entity that meets the definition of an inverted domestic corporation under 6 U.S.C. 395(b), applied in accordance with the rules and definitions of 6 U.S.C. 395(c).

“Manufactured end product” means any end product in product and service codes (PSCs) 1000-9999, except—

(1) PSC 5510, Lumber and Related Basic Wood Materials;

(2) Product or Service Group (PSG) 87, Agricultural Supplies;

(3) PSG 88, Live Animals;

(4) PSG 89, Subsistence;

(5) PSC 9410, Crude Grades of Plant Materials;

(6) PSC 9430, Miscellaneous Crude Animal Products, Inedible;

(7) PSC 9440, Miscellaneous Crude Agricultural and Forestry Products;

https://www.sam.gov/ https://www.acquisition.gov/content/52204-25-prohibition-contracting-certain-telecommunications-and-video-surveillance-services-or-equipment#id1989I600I4C http://uscode.house.gov/view.xhtml?req=granuleid:USC-prelim-title6-section395&num=0&edition=prelim http://uscode.house.gov/view.xhtml?req=granuleid:USC-prelim-title6-section395&num=0&edition=prelim

(8) PSC 9610, Ores;

(9) PSC 9620, Minerals, Natural and Synthetic; and

(10) PSC 9630, Additive Metal Materials.

“Place of manufacture” means the place where an end product is assembled out of components, or otherwise made or processed from raw materials into the finished product that is to be provided to the Government. If a product is disassembled and reassembled, the place of reassembly is not the place of manufacture.

“Predecessor” means an entity that is replaced by a successor and includes any predecessors of the predecessor.

“Restricted business operations” means business operations in Sudan that include power production activities, mineral extraction activities, oil-related activities, or the production of military equipment, as those terms are defined in the Sudan Accountability and Divestment Act of 2007 (Pub. L. 110-174).

Restricted business operations do not include business operations that the person (as that term is defined in Section 2 of the Sudan Accountability and Divestment Act of 2007) conducting the business can demonstrate—

(1) Are conducted under contract directly and exclusively with the regional government of southern Sudan;

(2) Are conducted pursuant to specific authorization from the Office of Foreign Assets Control in the Department of the Treasury, or are expressly exempted under Federal law from the requirement to be conducted under such authorization;

(3) Consist of providing goods or services to marginalized populations of Sudan;

(4) Consist of providing goods or services to an internationally recognized peacekeeping force or humanitarian organization;

(5) Consist of providing goods or services that are used only to promote health or education; or

(6) Have been voluntarily suspended.“Sensitive technology”—

“Sensitive technology”—

(1) Means hardware, software, telecommunications equipment, or any other technology that is to be used specifically—

(i)To restrict the free flow of unbiased information in Iran; or

(ii)To disrupt, monitor, or otherwise restrict speech of the people of Iran; and

(2) Does not include…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .