Attachment 1 - Statement of Work (SOW) (08.31.2022).pdf
PDF 808 KB Posted
- Attached to
- Desktop MFD, Printer, Scanner and Toner Multiple Award IDIQ Federal contract opportunity
- Solicitation number
- SP7000-22-R-1003
- Issued by
- Defense Logistics Agency
View the file
Other files for this federal contract opportunity
Show all 20
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Attachment 1 Statement of Work (SOW) Version 22.1
I. OVERVIEW
A. The Defense Logistics Agency (DLA) seeks to enter into up to 60-month multiple award Indefinite Delivery Indefinite Quantity (IDIQ) contracts with a total estimated maximum of up to $17 Million for the purchase of A4 desktop Multifunctional Devices (MFDs), desktop printers, flatbed scanners and accessories (hereafter collectively referred to as “devices”) within the 50 United States, District of Columbia to include non-foreign Outside Continuous United States (OCONUS) locations Guam and Puerto Rico. Specific details are found in sections II and III.
B. The services associated with the devices sought are delivery (Section IV), manufacturer’s warranty
(Section V), model substitutions (Section VI), reports (Section VII), network functionality (Section IX), and network security (Section X).
II. DEVICES AND CONFIGURATIONS (SEE ATTACHMENT 1 FOR QUICK REFERENCE MATRIX)
A. All devices shall meet the following requirements:
1. Equipment shall be Trade Agreement Act (TAA) compliant and manufactured new (not rebuilt, refurbished or remanufactured). New means composed of previously unused components, whether manufactured from virgin material, recovered material in the form of raw material, or materials and by-products generated from, and reused within, an original manufacturing process;
provided that the supplies meet contract requirements, including but not limited to, performance, reliability, and life expectancy.
2. Support Microsoft Windows 10 or higher and MacOS 11 or higher desktop operating system and Microsoft Server 2012 or higher server operating systems.
3. Delivered with up-to-date software/firmware and drivers, with 32-bit and 64-bit architecture driver support. Provide all subsequent updates along with installation instructions to DLA at no additional cost to the Government.
4. Capable of operating using 120 Volts, 60 Hertz.
5. Include a printed or digital (via compact disc (CD) or download link) operator’s manual, in English, for each device.
6. Devices shall be configured for table-top use.
B. All printers and MFDs shall meet the following requirements:
1. SIPR-capable devices, to include required SIPR tokens.
2. Operate using at least 30% recycled 20 lb. paper.
3. Media size/weight capability: 20lb bond up to 8.5” inch x 14”; 90lb index up to 8.5” x 11”; 20lb bond #10 envelopes; and 8.5” x 11” labels.
4. Print resolution of at least 600 x 600 dots per inch (DPI).
5. A minimum of 512 Megabyte (MB) of document management memory for monochrome devices and 1 Gigabyte (GB) of document management memory for color-capable devices.
6. Print drivers shall be capable of Page Description Language (PDL) to support Adobe PS3 and PCL6.
7. Capable of being configured with an additional, 500-sheet minimum, paper tray.
C. All MFDs shall meet the following additional requirements:
1. Capable of printing, copying, scanning, and faxing. SIPR designated devices shall NOT have faxing capability.
2. Simplex/duplex copying, printing, and scanning.
3. Collated output.
4. Automatic Document Feeder (ADF) for copying and scanning with a 50-sheet minimum capacity.
5. Capable of producing a minimum of 99 copies; reduction and enlargements of 25% to 400%.
6. Scanner capable of color scanning with both monochrome and color MFDs, with a minimum optical scan resolution of 600 x 600 DPI.
D. All printers shall meet the following additional requirements:
1. Simplex/duplex printing.
2. Collating.
E. All scanners shall meet the following requirements:
1. Minimum 8.5” x 11” flatbed with document feeder.
2. Capable of color scanning, with a minimum optical scan resolution of 600 DPI; minimum output bit depth of 24-bit color, 8-bit grayscale.
3. USB 2.0 or 3.0 connectivity.
4. Capable of outputting the following file formats: JPG, TIFF, and PDF (searchable). Device shall include optical character recognition (OCR) software to convert scanned documents to text and common word processing file formats to include Microsoft Word.
5. Ability to retrieve scanned image files with Windows or MAC signed Technology Without An Interesting Name (TWAIN) drivers. TWAIN drivers shall be included with each device.
F. All devices shall meet the following security requirements:
1. Devices with hard drives (platter or solid state) shall have an encryption or overwrite Security Kit.
2. All SIPR designated devices shall either be configured without hard drives (preferred) or if configured with hard drives they shall include removable hard drive kits with installation instructions.
3. Unused ports, protocols and services on each device shall be able to be enabled/disabled by the local IT administrator.
4. All desktop MFDs shall have a secure scanning functionality that complies with Federal Information Processing Standard (FIPS) 140-2 or 140-3 encryption.
5. All Non-Classified Internet Protocol Router (NIPR) desktop MFDs shall have analog fax only. Note:
The analog fax function shall be configured to separate/isolate the fax controller from the network controller. SIPR designated devices shall NOT have fax capability.
6. All desktop MFDs:
a. Shall have Common Access Card (CAC)/Personal Identity Verification (PIV) enablement in order to secure the device from unauthorized use and shall have a “Secure Print” feature that allows end-users to use authentication credentials (ex. ID, Login) and password identification (PIN) to release print jobs on the device.
b. Shall be capable of integration with print on-demand solution (e.g., equivalent to “Follow Me,” “Follow You,” “Push” or “Pull” printing) that shall allow end-users to release print output on any device on the network.
c. Shall have secure scanning functionality with routing and integration to standard DoD network infrastructure destinations.
G. Contractors shall provide original equipment manufacturer (OEM) specification sheets and proposed configurations for each device with proposal to the Contracting Officer.
III. VOLUME BAND SPECIFICATIONS:
A. In addition to the features/capabilities/configurations set forth in section II (outlined above), the
Contractor shall provide all devices in accordance with the chart below:
VOLUME
BAND
NIPR
SIPR
MONO/
COLOR
MINIMUM SPEED*
Pages per Minute
(Letter)
PAPER CAPACITY
VB-1 MFD NIPR Mono 45 One (1) Bypass Tray [100 Sheet Minimum] - Up to 8.5” x 14” One (1) Adjustable Paper Tray [250 Sheet Minimum/Tray] - Up to 8.5” x 14”
VB-1 MFD SIPR Mono 45 One (1) Bypass Tray [100 Sheet Minimum] - Up to 8.5” x 14” One (1) Adjustable Paper Tray [250 Sheet Minimum/Tray] - Up to 8.5” x 14”
VB-2 MFD NIPR Mono 65 One (1) Bypass Tray [100 Sheet Minimum] - Up to 8.5” x 14” One (1) Adjustable Paper Tray [500 Sheet Minimum/Tray] - Up to 8.5” x 14”
VB-2 MFD SIPR Mono 65 One (1) Bypass Tray [100 Sheet Minimum] - Up to 8.5” x 14” One (1) Adjustable Paper Tray [500 Sheet Minimum/Tray] - Up to 8.5” x 14”
VB-1 MFD NIPR Color 35 One (1) Bypass Tray [100 Sheet Minimum] - Up to 8.5” x 14” One (1) Adjustable Paper Tray [250 Sheet Minimum/Tray] - Up to 8.5” x 14”
VB-1 MFD SIPR Color 35 One (1) Bypass Tray [100 Sheet Minimum] - Up to 8.5” x 14” One (1) Adjustable Paper Tray [250 Sheet Minimum/Tray] - Up to 8.5” x 14”
VB-2 MFD NIPR Color 50 One (1) Bypass Tray [100 Sheet Minimum] - Up to 8.5” x 14” One (1) Adjustable Paper Tray [500 Sheet Minimum/Tray] - Up to 8.5” x 14”
VB-2 MFD SIPR Color 50 One (1) Bypass Tray [100 Sheet Minimum] - Up to 8.5” x 14” One (1) Adjustable Paper Tray [500 Sheet Minimum/Tray] - Up to 8.5” x 14”
VB-1 PRT NIPR Mono 45 One (1) Bypass Tray [100 Sheet Minimum] - Up to 8.5” x 14” One (1) Adjustable Paper Tray [250 Sheet Minimum/Tray] - Up to 8.5” x 14”
VB-1 PRT SIPR Mono 45 One (1) Bypass Tray [100 Sheet Minimum] - Up to 8.5” x 14” One (1) Adjustable Paper Tray [250 Sheet Minimum/Tray] - Up to 8.5” x 14”
VB-2 PRT NIPR Mono 65 One (1) Bypass Tray [100 Sheet Minimum] - Up to 8.5” x 14” One (1) Adjustable Paper Tray [500 Sheet Minimum/Tray] - Up to 8.5” x 14”
VB-2 PRT SIPR Mono 65 One (1) Bypass Tray [100 Sheet Minimum] - Up to 8.5” x 14” One (1) Adjustable Paper Tray [500 Sheet Minimum/Tray] - Up to 8.5” x 14”
VB-1 PRT NIPR Color 35 One (1) Bypass Tray [100 Sheet Minimum] - Up to 8.5” x 14” One (1) Adjustable Paper Tray [250 Sheet Minimum/Tray] - Up to 8.5” x 14”
VB-1 PRT SIPR Color 35 One (1) Bypass Tray [100 Sheet Minimum] - Up to 8.5” x 14” One (1) Adjustable Paper Tray [250 Sheet Minimum/Tray] - Up to 8.5” x 14”
VB-2 PRT NIPR Color 50 One (1) Bypass Tray [100 Sheet Minimum] - Up to 8.5” x 14” One (1) Adjustable Paper Tray [500 Sheet Minimum/Tray] - Up to 8.5” x 14”
VB-2PRT SIPR Color 50 One (1) Bypass Tray [100 Sheet Minimum] - Up to 8.5” x 14” One (1) Adjustable Paper Tray [500 Sheet Minimum/Tray] - Up to 8.5” x 14”
VB-1 SCN NIPR Color 25 (50 IPM) ADF Capacity: 35 Sheet Minimum; 600 DPI optical resolution
VB-2 SCN NIPR Color 40 (80 IMP) ADF Capacity: 50 Sheet Minimum; 600 DPI optical resolution
VB-3 SCN NIPR Color 80 (160 IPM) ADF Capacity: 80 Sheet Minimum; 600 DPI optical resolution
(*PPM listed for printers and MFDs reflect number of single-sided monochrome or color 8.5” x 11” sheets the device is capable of printing per minute; PPM listed for scanners reflect number of single-sided color 8.5” x 11” sheets and number of double-sided (impressions per minute (IPM)) color 8.5” x 11” sheets the device is capable of scanning.)
B. High-capacity toner cartridges for MFDs and printers shall be available to order as additional CLINs.
Toner cartridges for monochrome devices shall have a minimum yield of 10,000 impressions. Toner cartridges for volume band 1 (VB-1) color-capable devices shall have a minimum yield of 8,500 black impressions and 5,000 cyan/magenta/yellow impressions, and toner cartridges for volume band 2 (VB-2) color-capable devices shall have a minimum yield of 10,000 cyan/magenta/yellow/black impressions.
C. Additional paper tray (minimum 8.5 x 11” paper size; 500 sheet minimum capacity) shall be available to purchase as an option for all MFD and printers
IV. DELIVERY
A. Delivery of Ordered Devices:
1. Delivery of ordered devices shall be in accordance with (IAW) the timeframes outlined in the chart below:
Amount of Devices Per Contracting Action
Maximum Number of Calendar Days to Complete Delivery and Installation
Up to 10 15 days after receipt of order (ARO)
11-100 30 days ARO
101 – 250 45 days ARO
More than 250 60 days ARO
2. Upon completion of device delivery, the Contractor shall obtain customer signature and date on each bill of lading (BOL) or packing slip and provide this proof of delivery to the designated DLA point of contact (DLA POC) within ten (10) business days after delivery. The Contractor shall also provide the Delivery Report (Appendix #1) or a modified delivery schedule with serial numbers added to the designated DLA POC within ten (10) business days after delivery and installation have been completed.
3. If a device cannot be delivered within the delivery time that is given, the Contractor shall notify the issuing Contracting Officer as soon as the delay is realized, of the expected delivery date for the ordered device(s).
V. MANUFACTURER’S WARRANTY
A. The Contractor shall provide a minimum one (1), three (3), and five (5) year manufacturer’s warranty with each device to replace or repair defective devices. The Contractor shall respond to requests for repairs within two (2) business days of initial contact by the Customer.
B. All warranties shall include defective media retention and onsite service/repair if the proposed device has an internal hard drive.
C. If it chooses to repair on-site, the Contractor must ensure all service technicians are eligible for access to Department of Defense facilities in accordance with the authority in DoD manual 5200.08 Volume 3, which establishes DoD access control policy and the minimum DoD security standards for controlling entry to DoD installations and stand-alone facilities. Contractors must also check and follow installation access policies specific to each DoD installation. Technicians must be eligible for access at time of the award. In addition, in the case of devices cleared for CLASSIFIED material, the contractor’s repair technicians shall ensure they do not access the device without a Government employee escort present and observing during the support/repair services. To ensure an escort is present the Contractor shall call the Customer a minimum of 24 hours prior to the site visit to schedule the time of arrival.
VI. MODEL SUBSTITUTIONS
A. In the event the Contractor is no longer able to provide the products proposed, the Contractor may, only after written approval by the Contracting Officer, provide replacement devices which shall meet or exceed the requirements as listed in this SOW, at the contract price.
B. Prior to delivery, if replacement devices have not been previously tested by DLA, they shall be tested as outlined in Section XI.
C.
VII. REPORTS
A. The Contractor shall provide the following report:
1. Delivery Report (Appendix #1), as referenced in Section IV.A.2, which shall contain an accurate listing of all devices under contract (model, serial number, location). This report shall be submitted to the DLA POC.
VIII. INVOICING
A. All invoices shall be submitted via Wide Area Work Flow (WAWF) and shall be submitted in United States Dollars. The following website provides additional information regarding WAWF including information for “vendors getting started” with the system:
https://wawf.eb.mil/xhtml/unauth/help/help.xhtml.
IX. NETWORK FUNCTIONALITY FOR MFDS AND PRINTERS
A. DOD policy prohibits the publication of network configuration information; therefore, DOD installations shall not fill out pre-installation site surveys. The required information shall be provided at time of installation.
B. The Contractor shall provide devices that shall operate on and coexist on a network supporting all of the following:
1. Internet Protocol Version 4 (IPv4),
2. Internet Protocol Version 6 (IPv6),
3. A hybrid of IPv4 and IPv6.
C. The Contractor shall provide documentation and support to DLA for STIG compliant network configurations based on agency hardware/software (see section X.A. below).
X. NETWORK SECURITY FOR MFDS AND PRINTERS
A. The Contractor shall provide devices that can be configured to comply with the current Defense Information Systems Agency (DISA) Security Technical Implementation Guide (STIG) titled Multifunction Device and Network Printer STIG (latest version and release), available at:
https://cyber.mil/.
B. All devices shall support Simple Network Management Protocol (SNMP) version 3 (v3). Versions 1 and 2 (SNMPv1/SNMPv2) shall be disabled.
C. All hard drives that are put into service within Federal agencies shall remain in their custody. In the instance where a device is removed by the Contractor, all hard drives, whether internal, external, or otherwise, shall remain in possession of the Government and not be removed with the device.
D. Contractors shall monitor industry standard vulnerability sites (e.g. http://nvd.nist.gov/, https://www.us-cert.gov/ncas/alerts, http://oval.mitre.org/) and take appropriate actions if their equipment is subject to a known vulnerability. When vulnerabilities are identified by the Contractor, DLA or its customers, the Contractor shall provide remediation for distribution to all installed equipment in accordance with USCYBERCOM TASKORD regulations unless a different time period is directed by USCYBERCOM via DLA. The TASKORD is Controlled Unclassified Information (CUI). The following is authorized to be quoted from the TASKORD for reference:
1. Assured Compliance Assessment Solution (ACAS) assigns severity scores of critical, high, medium and low to plug-in findings.
https://wawf.eb.mil/xhtml/unauth/help/help.xhtml https://cyber.mil/ http://nvd.nist.gov/ https://www.us-cert.gov/ncas/alerts http://oval.mitre.org/
a. Critical findings reflect discovery of a common vulnerability and exposure (CVE) that poses significant risk to the confidentiality, integrity, and availability of DODIN Networks. Actions to mitigate or remediate critical vulnerabilities shall be initiated upon discover with the goal of mitigation/remediation within seven (7) calendar days.
b. Findings with a severity score of high shall be addressed in the same manner as vulnerabilities addressed via Information Assurance Vulnerability Alert (IAVA) directives and mitigated or remediated within twenty-one (21) calendar days of discovery.
c. Findings with severity scores of medium and low shall be addressed in accordance with local Approving Official (AO), Information System Security Manager (ISSM), or Information System Security Officer (ISSO) guidance until further notice.
d. In all instances, DOD components shall consider exposure to threat, mission impact, sensitivity of data, and current mitigating security controls when prioritizing implementation of fix actions.
E. In the event remediation cannot be achieved within the mandated timeline, the Contractor shall provide a Plan of Action and Milestones and receive approval thereof by the Customer’s agency Authorizing Official or designee for risk acceptance.
F. All MFDs and printers shall be International Organization for Standardization (ISO)/International Electrotechnical Commission (IEC) 15408 (Common Criteria) certified IAW CNSSP-11 using the National Information Assurance Partnership (NIAP) approved criteria or equivalent.
1. A device shall be acceptable if it is included on either the NIAP CCEVS Product Compliant List (https://www.niap-ccevs.org/Product/) or Common Criteria Portal Certified Products list (http://www.commoncriteriaportal.org/products/).
2. All devices shall have current ISO/IEC 15408 certification and recertification, if applicable, before the Contractor can schedule lab time for testing. See section XI F. Guidance for Common Criteria Maintenance and Reevaluation is available at: https://www.niap-ccevs.org/documents_and_guidance/ ccevs/ scheme-pub-6.pdf
G. All devices shall be capable of obtaining accreditation through the Risk Management Framework (RMF) for DOD Information Technology (IT). As part of this, the Contractor agrees to provide all requested information and work in good faith with DLA so the DLA customers can expeditiously obtain RMF accreditation prior to device delivery and installation. The Contractor shall also provide devices for vulnerability and STIG testing to DLA or customer’s site at no cost to the Government. The Contractor further agrees that if the proposed device(s) does not obtain RMF accreditation, the contractor shall remove the device(s). Information regarding RMF is found in Risk Management Framework (RMF) for DOD Information Technology (IT) Instruction 8510.1 dated 12 March 2014:
http://www.dtic.mil/whs/directives/corres/pdf/851001_2014.pdf. In order to maintain RMF and STIG compliance, devices are required to be delivered with the most up-to-date firmware, as outlined in section II.A.10.
H. For all MFDs, at time of delivery, the Contractor shall:
1. Supply a SMARTCARD Public Key Infrastructure (PKI) Solution which is compliant with DODI
8520.03 and NIST FIPS 201 (PIV) standards. The contractor shall provide card readers that shall read and process all approved CAC and PIV cards. The Contractor shall maintain compliance with DOD-wide SMARTCARD and DOD PKI standards and support all approved physical cards during the full lease period.
2. Provide a SMARTCARD PKI Solution with SIPRNet token capability, which is compliant with DOD requirements for PK-enabling and interoperability as set forth in DODI 8520.02. The Contractor shall provide card readers that shall read and process all approved SIPRNet token cards. The Contractor shall provide device support systems that incorporate the use of PKI for encryption of https://www.niap-ccevs.org/Product/ http://www.commoncriteriaportal.org/products/ https://www.niap-ccevs.org/documents_and_guidance/%20ccevs/%20scheme-pub-6.pdf https://www.niap-ccevs.org/documents_and_guidance/%20ccevs/%20scheme-pub-6.pdf http://www.dtic.mil/whs/directives/corres/pdf/851001_2014.pdf information in transit or at rest. The Contractor shall provide devices that are compatible with 3.3 volt SafeNet SC650 token and that are compatible with the 90Meter Middleware solution for CAC, known as CAC Smart Card Manager-90. For current DODI instructions go to:
http://www.dtic.mil/whs/directives/corres/ins1.html.
3. Ensure that CAC/SIPR token authentication is available for scanning, printing and copying and shall be:
a. Capable of digitally signing emails using the senders DOD PKI Certificate(s).
b. Capable of encrypting emails using the receivers DOD PKI Certificate(s).
c. Capable of scan-to-file on networked devices.
d. In compliance with Homeland Security Presidential Directive-12 (HSPD-12).
I. The Contractor shall produce certificates of compliance, if requested.
XI. TESTING
A. All devices proposed in response to the contract shall be tested for compliance with Network Security as defined in section X after award. The Contractor shall deliver the devices for each Volume Band series, under each Functional Area, to DLA Information Operations J67E located at 430 Mifflin Avenue, Building 430, New Cumberland, PA 17070, for testing, at no cost to the government. Delivery coordination shall take place within five (5) business days of contract award. The MFD Configuration Manager can be reached at (717) 265-3131.
B. The estimated time for DLA testing is twenty (20) business days per device. Testing and approval shall be performed by the DLA Information Operations EMS Division in conjunction with the Contractor’s assistance. The Contractor shall provide onsite engineering assistance and other support necessary to configure, setup, and test the equipment as needed at no additional cost to the Government.
1. DLA tests devices to meet DOD RMF and STIG Compliance when applicable. If all devices pass the preliminary testing process, DLA shall submit a compliance memorandum to the Contractor informing them that the devices have passed the preliminary testing process. DLA reserves the right to offer devices to Customers after all devices in a particular category (MFD/printer/scanner) from all Contractors have been tested. In some cases, prior to being added to the DLA customer’s network, additional certification procedures and testing shall be required prior to risk acceptance.
If required by DLA, the Contractor shall deliver test devices to the DLA customer prior to proceeding with installation. DLA shall exercise due diligence to assist with technical mitigation and resolve any questions and/or concerns raised by that agency during the testing review process.
2. Upon request, the Contractor shall provide a representative device from each common criteria certified family and engineering support to the NAVWAR test facility at Naval Base Point Loma in San Diego, CA for all devices that are to be placed on the Navy & Marine Corps Intranet (NMCI).
After DLA testing is completed, NMCI testing shall begin after DLA is able to schedule devices for NMCI testing. All devices shall be tested to operate on the NMCI for the "printer, scanner and fax" functions. The NMCI Testing Checklist (Appendix #2) outlines what functionalities will be tested to operate on the NMCI network prior to placement of devices on the NMCI Certified Device List (CDL). The Device Manufacturer Questionnaire (Appendix #3) shall be provided to the NAVWAR test facility prior to delivery. The NMCI certification process can take from four to six (4 to 6) months. This is in addition to the 20 days required for DLA testing as mentioned in section IX.B above. No orders shall be placed for NMCI devices until all awardees pass NMCI testing in a particular category (MFD/Printer/Scanner)
3. For devices ordered to be installed on Navy networks in Guam, the Contractor shall provide networked equipment that shall be tested to operate Outside the Contiguous United States (OCONUS) Navy Enterprise Network (ONE-Net) for the "printer, scanner and fax" functions. This http://www.dtic.mil/whs/directives/corres/ins1.html equipment shall be accredited to operate and added to the ONE-Net Approved Products List (APL) prior to the delivery of devices. The ONE-Net approval process requires an additional one hundred thirty (130) days. This is in addition to the 20 days required for DLA testing as mentioned in section IX.B above.
4. If the devices do not pass any of the testing procedures for any reason, DLA shall not proceed with installation of said devices at the customer locations and DLA shall terminate the contract.
C. A device shall not be tested if it cannot be assigned to one of the Volume Bands as outlined in section
III.
D. The devices shall be delivered with all required accessories, software, firmware, etc. Output paper handling accessories are not tested and shall not be delivered to the lab.
E. Approved devices previously submitted to DLA for testing are not required to be re-tested.
F. The Contractor shall deliver the devices for each Volume Band series, under each Functional Area, to DLA Information Operations J67E located at 430 Mifflin Avenue, Building 430, New Cumberland, PA 17071, for testing, at no cost to the government. Delivery coordination shall take place within five (5) business days of contract award.
G. The Contractor shall resolve non-compliance issues as quickly as possible. If the issues cannot be resolved within fourteen (14) calendar days, the test shall be suspended. After the non-compliance issues are resolved by the Contractor, the suspended session shall be scheduled when lab time is next available. If requested by DLA, the Contractor shall remove their devices from the lab to avoid delaying the next scheduled test at no additional cost to the Government.
H. For all devices tested and placed on the DLA contract, the Contractor shall collaborate with the DLA Configuration Manager to develop the testing results package. The Contractor shall develop the device Implementation Guide. The Implementation Guide shall provide step-by-step instructions and screenshots to configure the devices in accordance with the testing results. Government acceptance of the Implementation Guide is at the discretion of the DLA EMS Division.
I. The security requirements set forth in this SOW are minimum device specifications and have been identified as the basic requirements common across Government agencies. These are the minimum security requirements applicable to all devices awarded under this contract. Each ordering activity may have its own hardware/software acceptance processes. All devices shall be subject to ordering activity hardware/software evaluation processes at the order level. If the device fails a security evaluation, the Contractor may select a different technology or mitigate the failed controls to fulfill this requirement.
The Contractor shall be available to meet with the information technology (IT) and security personnel at a mutually convenient time during the evaluation process and shall identify a mutually acceptable solution. The Contractor shall provide the necessary equipment or expertise to complete security testing and integration into the existing environment. At the order level, the customer agency may require the Contractor to ship devices to a specific location for testing at time of order award.
J. If, during the life of the contract, a requirement in section IX and X is changed, updated or revised, the Contractor shall comply with the most current version of the requirement.
K. The Contractor shall remove all hardware from the DLA test lab within fourteen (14) calendar days upon notification of test completion at no additional cost to the Government.
XII. SUPPLY CHAIN RISK MANAGEMENT
A. As part of its proposal, the Contractor shall provide written documentation demonstrating how the integrity and security of all equipment, components thereof, repair parts and consumables it will provide and/or use in performing this contract will meet the standards set forth in National Institute of Standards and Technology (NIST) Special Publication 800-161. This documentation shall clearly demonstrate how the Contractor is taking effective measures to mitigate the risks of foreign intelligence services, terrorist groups, or others from inserting unwanted functionality into the supplies and/or services DLA receives through this contract. Additionally, this documentation shall provide specific details of what—
1. Policies the Contractor has in place to prevent both (a) the use of counterfeit or altered equipment, components thereof, consumables and parts and (b) their introduction into the Contractor’s supply chain;
2. Security procedures the Contractor uses to track the chain of custody of equipment, components thereof, consumables and parts, to include while this material is in storage and in transit; and
3. Steps the Contractor takes to ensure the integrity and authenticity of equipment, components thereof, repair parts and consumables to prevent tampering so they will perform according to specifications without additional unwanted functionality.
B. The Contractor shall continuously meet the standards of NIST Special Publication 800-161 while taking effective measures to mitigate the risks of foreign intelligence services, terrorist groups, or others from inserting unwanted functionality into the supplies and/or services provided through this contract.
Upon request, the Contractor shall provide written documentation meeting all requirements set forth in part A, above.
XIII. INSTALLATION SECURITY REQUIREMENTS
A. The Contractor shall comply with all Federal, DoD and local rules and regulations to obtain Government installation access in order to meet all response times identified within the PWS.
B. The Contractor shall comply with Government base access requirements as set forth in the base/ command regulations.
C. The Contractor shall be responsible for any and all fees associated with the application process and/or enrollment to access any installation or facility.
D. For devices cleared for CLASSIFIED material, the Contractor’s repair technicians shall have a DOD security clearance equal to or higher than the classification of the device and shall provide verification when requested.
XIV. GENERAL CONDITIONS
A. The Contractor shall assign a single point of contact (POC) to coordinate with the Contracting Officer in all aspects of this contract within three (3) business days of receipt of the order. The Contractor shall provide its assigned POC’s name, title, business address, phone number and email address to the Contracting Officer.
B. The Contractor shall comply with the Health Insurance Portability and Accountability Act (HIPAA) when installing devices at Government medical sites.
C. The Contractor shall comply with the Section 508 accessibility requirements. By submission of its offer, the Contractor affirms that its Electronic Information Technology (EIT) supplies and services are accessible as outlined in the law, the standard, and FAR Subpart 39.2. The Contractor shall submit their completed Voluntary Product Accessible Template (VPAT®) or the provided VPAT document (Appendix #4) with their proposal.
XV. APPENDICES
A. Appendix #1: Delivery Report
B. Appendix #2: NMCI Testing Checklist
C. Appendix #3: Device Manufacturer Questionnaire
D. Appendix #4: VPAT® Template
Appendix #1 DELIVERY REPORT
Activity Name Customer Address
Customer POC Phone # Customer POC Email
Contract #
CLIN#
Manufacturer
Model #
Serial #
Delivery Date
Building Number
Floor Number/ Room Number
Continue on the back, if needed. Note: A Delivery Schedule or Spreadsheet can be used as an attachment to this delivery report.
Customer Accepting Receipt of Device (Print): Customer Signature
CLIN#
Manufacturer
Model #
Serial #
Install Date
Building Number
Floor Number/ Room Number
(Page 2 – Appendix #1)
NO
FUNCTION YES
Print Function Print monochrome, default to grayscale and draft mode Print color, default to grayscale and draft mode Print duplex & simplex with duplex default Print portrait & landscape Support PCL5 or PCL6, and Post Script Support multiple paper sizes: letter, legal, A4 Support image enlargement, reduction, and page fit Multi-position stapler finisher
Scan function Scan to email w/CAC authentication - sign and encrypt messages DIRECT/NATIVE Scan to Command Folder or H: drive using CAC authenticated credentials Scan via Autostore Scan output in PDF and TIFF format Scan color input and output Scan to Network folder without CAC
Fax function Modem-to-modem analog fax using industry standard speeds and error correction Disable network fax option if available
Copy function Copy all possible simplex/duplex options Support multiple paper sizes: Letter, Legal, A4 Image enlargement/reduction Automatic document feeder and flatbed copy Color copy input and output
Miscellaneous options NIAP compliant MFD and Network Print STIG compliant Secure print (CAC enabled Print) Secure print (User PIN/PW) SMARTCARD PKI solution compliant with DOD CAC and NIST FIPS 201 (PIV) standards Fax and scan under CAC control, print and copy set to walk up HDD overwrite or encryption Energy Settings - Default Sleep Mode SIPR/Classified NIPR/Unclassified
Primary test model Member of same model family
Appendix #2 – NMCI TESTING CHECKLIST
Appendix #3 PROPRIETARY
Device Manufacturer Questionnaire SCLIN x049 Network Hardware Certification
Leidos – NMCI Enterprise Engineering The purpose of this document is to gather the required information from hardware manufacturers for the engineering team prior to devices being certified and available for use within NMCI.
1. Device to be certified:
Manufacturer/Make:
Device Model:
Driver/Software Version:
Firmware Version:
2. Is the hardware TAA Compliant?
Yes No
3. Vendor Technical Point of Contact (Person that can verify instructions for installing, testing, ports, and configuration of the software):
Name:
Phone:
Email:
Time Zone:
4. Has the device previously been certified for use within NMCI?
Yes No
If yes, using what version of firmware and drivers?
Firmware Version:
Driver/Software Version:
5. Is this a network device?
Yes No
If yes, is it compatible with Windows Server 2008?
Yes No
6. If this is a multi-function device, is it currently compatible with the certified NMCI Autostore Express Scan to File Solution Version 5.0?
Yes No Does it utilize user authentication or FTP to communicate to Autostore Express?
User Authentication FTP
7. If this is a multi-function device what version of Firmware and Drivers does this device require for it to function with NMCI Autostore Express Scan to File:
Firmware:
Driver:
Other added hardware, chipsets, internal cards: .
Final, Version 2.0, September 21, 2021 NMCI/SMIT
Use or disclosure of data in this document is subject to the restrictions on this page.
8. What ports are required for this device to communicate?
All open ports must be documented for operation of device.
Port Number: Port Number:
Port Number: Port Number:
Port Number: Port Number:
Additional TCP/IP or UDP ports that are open on device and are not required for printing or scanning.
Port Number: Port Number:
Port Number: Port Number:
Port Number: Port Number:
Please provide written technical instructions how to configure and close unused network ports on this device.
9. If device requires an administrative account for access to the set up please provide Account “name” and Account “password”.
Account Name:
Account Password:
10. If device requires an administrative account for access to an embedded web service please provide Account “name” and Account “password”.
Account Name:
Account Password:
11. Instructions to reset device back to factory default settings:
Instructions:
GOVERNMENT PURPOSE RIGHTS
Contract No. N00039-20-D-0054
Contractor Name: Leidos Contractor Address 1750 Presidents Street Reston, VA, 20190
The Government's rights to use, modify, reproduce, release, perform, display, or disclose this technical data/computer software are restricted by clause H-8 contained in the above identified contract. Any reproduction of this technical data/computer software or portions thereof marked with this legend must also reproduce the markings
Final, Version 2.0, September 21, 2021 NMCI/ SMIT Use or disclosure of data in this document is subject to the restrictions on this page.
Appendix #4
[Company] Accessibility Conformance Report
(Based on VPAT® Version 2.4)
Name of Product/Version:
Report Date:
Product Description:
Contact Information:
Notes:
Evaluation Methods Used:
Applicable Standards/Guidelines
This report covers the degree of conformance for the following accessibility standard/guidelines:
Standard/Guideline Included In Report Web Content Accessibility Guidelines 2.0 Level A (Yes / No )
Level AA (Yes / No ) Level AAA (Yes / No )
Web Content Accessibility Guidelines 2.1 Level A (Yes / No ) Level AA (Yes / No )
Level AAA (Yes / No ) Revised Section 508 standards published January 18, 2017 and corrected January 22, 2018
(Yes / No )
EN 301 549 Accessibility requirements suitable for public procurement of ICT products and services in Europe, - V3.1.1 (2019-11)
(Yes / No )
Terms
The terms used in the Conformance Level information are defined as follows:
• Supports: The functionality of the product has at least one method that meets the criterion without known defects or meets with equivalent facilitation.
• Partially Supports: Some functionality of the product does not meet the criterion.
• Does Not Support: The majority of product functionality does not meet the criterion.
• Not Applicable: The criterion is not relevant to the product.
• Not Evaluated: The product has not been evaluated against the criterion. This can be used only in WCAG
2.0 Level AAA.
Revised Section 508 Report Notes:
Chapter 3: Functional Performance Criteria (FPC) Notes:
Criteria Conformance Level Remarks and Explanations
302.1 Without Vision.
Where a visual mode of operation is provided, ICT shall provide at least one mode of operation that does not require user vision.
302.2 With Limited Vision.
Where a visual mode of operation is provided, ICT shall provide at least one mode of operation that enables users to make use of limited vision.
302.3 Without Perception of Color. Where a visual mode of operation is provided, ICT shall provide at least one visual mode of operation that does not require user perception of color.
302.4 Without Hearing.
Where an audible mode of operation is provided, ICT shall provide at least one mode of operation that does not require user hearing.
302.5 With Limited Hearing.
Where an audible mode of operation is provided, ICT shall provide at least one mode of operation that enables users to make use of limited hearing.
302.6 Without Speech.
Where speech is used for input, control, or operation, ICT shall provide at least one mode of operation that does not require user speech.
302.7 With Limited Manipulation. Where a manual mode of operation is provided, ICT shall provide at least one mode of operation that does not require fine motor control or simultaneous manual operations.
302.8 With Limited Reach and Strength.
Where a manual mode of operation is provided, ICT shall provide at least one mode of operation that is operable with limited reach and limited strength.
302.8 With Limited Reach and Strength.
Where a manual mode of operation is provided, ICT shall provide at least one mode of operation that is operable with limited reach and limited strength.
302.9 With Limited Language, Cognitive, and Learning Abilities. ICT shall provide features making its use by individuals with limited cognitive, language, and learning abilities simpler and easier.
Chapter 4: Hardware
Criteria Conformance Level Remarks and Explanations
402.1 General. (Closed Functionality )
ICT with closed functionality shall be operable without requiring the user to attach or install assistive technology other than personal headsets or other audio couplers, and shall conform to 402.
Heading cell – no response required Heading cell – no response required
402.2.1 Information Displayed On-Screen.
Speech output shall be provided for all information displayed on-screen.
402.2.2 Transactional Outputs.
Where transactional outputs are provided, the speech output shall audibly provide all information necessary to verify a transaction.
402.2.3 Speech Delivery Type and Coordination.
Speech output shall be delivered through a mechanism that is readily available to all users, including, but not limited to, an industry standard
Criteria Conformance Level Remarks and Explanations connector or a telephone handset. Speech shall be recorded or digitized human, or synthesized. Speech output shall be coordinated with information displayed on the screen.
402.2.4 User Control.
Speech output for any single function shall be automatically interrupted when a transaction is selected. Speech output shall be capable of being repeated and paused.
402.2.5 Braille Instructions.
Where speech output is required by 402.2, braille instructions for initiating the speech mode of operation shall be provided. Braille shall be contracted and shall conform to 36 CFR part 1191, Appendix D, Section 703.3.1.
402.3.1 Private Listening.
Where ICT provides private listening, it shall provide a mode of operation for controlling the volume. Where ICT delivers output by an audio transducer typically held up to the ear, a means for effective magnetic wireless coupling to hearing technologies shall be provided.
402.3.2 Non-private Listening.
Where ICT provides non-private listening, incremental volume control shall be provided with output amplification up to a level of at least 65 dB. A function shall be provided to automatically reset the volume to the default level after every use.
402.4 Characters on Display Screens.
At least one mode of characters displayed on the screen shall be in a sans serif font. Where ICT does not provide a screen enlargement feature, characters shall be 3/16 inch (4.8 mm) high minimum based on the uppercase letter “I”. Characters shall contrast with their background with either light characters on a dark background or dark characters on a light background.
402.5 Characters on Variable Message Signs.
Characters on variable message signs shall conform to section 703.7 Variable Message Signs of ICC A117.1:2009.
403.1 Biometrics
Where provided, biometrics shall not be the only means for user identification or control.
404.1 Preservation of Information Provided for Accessibility
ICT that transmits or converts information or communication shall not remove non-proprietary information provided for accessibility or shall restore it upon delivery.
405.1 Privacy.
The same degree of privacy of input and output shall be provided to all individuals. When speech output required by 402.2 is enabled, the screen shall not blank automatically.
406.1 Standard Connections
Where data connections used for input and output are provided, at least one of each type of connection shall conform to industry standard non-proprietary formats.
407.2 Contrast.
Where provided, keys and controls shall contrast visually from background surfaces. Characters and symbols shall contrast visually from background surfaces with either light characters or symbols on a dark background or dark characters or symbols on a light background.
407.3.1 Tactilely Discernible.
Input controls shall be operable by touch and tactilely discernible without activation.
407.3.2 Alphabetic Keys.
Where provided, individual alphabetic keys shall be arranged in a QWERTY-based keyboard layout and the ‘‘F’’ and ‘‘J’’ keys shall be tactilely distinct from the other keys.
407.3.3 Numeric Keys.
Where provided, numeric keys shall be arranged in a 12-key ascending or descending keypad layout. The number five key shall be tactilely distinct from the other keys. Where the ICT provides an alphabetic overlay on numeric keys, the relationships between letters and digits shall conform to ITU?T Recommendation E.161
407.4 Key Repeat.
Where a keyboard with key repeat is provided, the delay before the key repeat feature is activated shall be fixed at, or adjustable to, 2 seconds minimum.
407.5 Timed Response.
Where a timed response is required, the user shall be alerted visually, as well as by touch or sound, and shall be given the opportunity to indicate that more time is needed.
407.6 Operation. (General)
At least one mode of operation shall be operable with one hand and shall not require tight grasping, pinching, or twisting of the wrist. The force required to activate operable parts shall be 5 pounds (22.2 N) maximum.
407.7 Tickets, Fare Cards, and Keycards.
Where tickets, fare cards, or keycards are provided, they shall have an orientation that is tactilely discernible if orientation is important to further use of the ticket, fare card, or keycard.
407.8.1 Vertical Reference Plane.
Operable parts shall be positioned for a side reach or a forward reach determined with respect to a vertical reference plane. The vertical reference plane shall be located in conformance to 407.8.2 or 407.8.3.
407.8.1.1 Vertical Plane for Side Reach. Where a side reach is provided, the vertical reference plane shall be 48 inches (1220 mm) long minimum.
407.8.1.2 Vertical Plane for Forward Reach. Where a forward reach is provided, the vertical reference plane shall be 30 inches (760 mm) long minimum.
407.8.2 Side Reach.
Operable parts of ICT providing a side reach shall conform to 407.8.2.1 or 407.8.2.2. The vertical reference plane shall be centered on the operable part and placed at the leading edge of the maximum protrusion of the ICT within the length of the vertical reference plane. Where a side reach requires a reach over a portion of the ICT, the height of that portion of the ICT shall be 34 inches (865 mm) maximum.
407.8.2.1 Unobstructed Side Reach.
Where the operable part is located 10 inches (255 mm) or less beyond the vertical reference plane, the operable part shall be 48 inches (1220
mm) high maximum and 15 inches (380 mm) high minimum above the floor.
407.8.2.2 Obstructed Side Reach.
Where the operable part is located more than 10 inches (255 mm), but not more than 24 inches (610 mm), beyond the vertical reference plane, the height of the operable part shall be 46 inches (1170 mm) high maximum and 15 inches (380 mm) high minimum above the floor. The operable part shall not be located more than 24 inches (610 mm) beyond the vertical reference plane.
407.8.3 Forward Reach.
Operable parts of ICT providing a forward reach shall conform to
407.8.3.1 or 407.8.3.2. The vertical reference plane shall be centered, and intersect with, the operable part. Where a forward reach allows a reach over a portion of the ICT, the height of that portion of the ICT shall be 34 inches (865 mm) maximum.
407.8.3.1 Unobstructed forward reach.
Where the operable part is located at the leading edge of the maximum protrusion within the length of the vertical reference plane of the ICT, the operable part shall be 48 inches (1220 mm) high maximum and 15 inches (380 mm) high minimum above the floor.
407.8.3.2 Obstructed Forward Reach.
Where the operable part is located beyond the leading edge of the maximum protrusion within the length of the vertical reference plane, the operable part shall conform to 407.12.3.2. The maximum allowable forward reach to an operable part shall be 25 inches (635 mm).
407.8.3.2.1 Height.
Where the operable part is located less than 20 inches (510 mm) beyond the vertical reference plane, the operable part shall be 48 inches (1220 mm) high maximum. Where the operable part is located 20 inches (510 mm) to 25 inches (635 mm) beyond the vertical reference plane, the operable part shall be 44 inches (1120 mm) high maximum.
407.8.3.2.2 Knee and Toe Space.
Knee and toe space under ICT shall be 27 inches (685 mm) high minimum, 25 inches (635 mm) deep maximum, and 30 inches (760
mm) wide minimum and shall be clear of obstructions.
408.2 Display Screens (General)
Where stationary ICT provides one or more display screens, at least one of each type of display screen shall be visible from a point located 40 inches (1015 mm) above the floor space where the display screen is viewed.
408.3 General. (Flashing)
Where ICT emits lights in flashes, there shall be no more than three flashes in any one-second period.
409.1 Status Indicators.
Status indicators, including all locking or toggle controls or keys (e.g., Caps Lock and Num Lock keys), shall be discernible visually and by touch or sound.
410.1 Color Coding.
Color coding shall not be used as the only means of conveying information, indicating an action, prompting a response, or distinguishing a visual element.
411.1 Audible Signals.
Where provided, audible signals or cues shall not be used as the only means of conveying information, indicating an action, or prompting a response.
412.2.1 Volume Gain for Wireline Telephones.
Volume gain conforming to 47 CFR 68.317 shall be provided on analog and digital wireline telephones.
412.2.2 Volume Gain for Non-Wireline ICT.
A method for increasing volume shall be provided for non-wireline ICT.
412.3.1 Wireless Handsets.
ICT in the form of wireless handsets shall conform to ANSI/IEEE C63.19-2011 (incorporated by reference, see 702.5.1).
412.3.2 Wireline Handsets.
ICT in the form of wireline handsets, including cordless handsets, shall conform to TIA-1083-B (incorporated by reference, see 702.9.1).
412.4 Digital Encoding of Speech.
ICT in IP-based networks shall transmit and receive speech that is digitally encoded in the manner specified by ITU-T Recommendation G.722.2 (incorporated by reference, see 702.7.2) or IETF RFC 6716 (incorporated by reference, see 702.8.1).
412.5 Real-Time Text Functionality (HCO and VCO Support)
Reserved. (Pending the outcome of rulemaking of the Federal Communications Commission(FCC) as discussed in Section III.D (Major Issues-Real-Time Text))
412.5 Real-Time Text Functionality (Interoperability) Reserved.
(Pending the outcome of rulemaking of the Federal
412.5 Real-Time Text Functionality (Compatibility with Interactive Voice Response).
Reserved. (Pending the outcome of rulemaking of the Federal
412.6 Caller ID.
Where provided, caller identification…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .