Statement_of_Work_SOW.pdf

PDF 1 MB Posted

Attached to
ROMO SERVICE & SUPPORT FOR AFMS Federal contract opportunity
Solicitation number
140P1226Q0040
Issued by
Department of the Interior National Park Service Intermountain Region

About this file

This is a Statement of Work for service, support, and maintenance of 11 automated fee machines (AFMs) at Rocky Mountain National Park. The AFMs are VenTek M600 AIO CORE MACHINE models with dimensions of 34" x 25" x 17", located at five entrance stations (Beaver Meadows, Fall River, Grand Lake, Wild Basin) and two trailheads (Lily Lake, Lumpy Ridge). Nine machines operate on AC power and two on solar power. Connectivity varies by location: ten machines use wireless cellular (AT&T or Verizon), and one uses satellite. One Fall River location requires both Quick-Pick and Pay-by-Space programming; all others use Quick-Pick programming.

The contractor must provide comprehensive services including configuration and support, technical support through a Service Level Agreement (SLA), hardware repairs, managed services for PCI compliance, software updates, credit card processing certification with Treasury-designated processor Vantiv, and compliance with PA-DSS and EMV chip-and-PIN standards. The contractor must acquire and manage wireless cellular connectivity for applicable sites. Technical support must be available 24/7 with response times of 30 minutes for urgent issues (95% resolution within two hours) and two hours for normal issues (95% resolution within four days). The AFMs must accept credit card payments only and include features for product pricing flexibility, discount application, receipt generation, user access management, and reporting. All equipment must comply with Section 508 accessibility and ADA requirements, with an IP54 dust and water intrusion rating, temperature operability between 0°F and 110°F, and security features including tamper-proof locks. The base contract period runs from August 1, 2026 to July 31, 2027, with four one-year option periods. Quarterly deliverables include technical support reports, managed services compliance documentation, and system administration reports. Travel costs and onsite support are reimbursable under GSA Federal Travel Regulations with no profit allowed. The contractor must maintain monthly transaction estimates (approximately 13,739 credit card transactions annually based on recent data) and provide spare parts pricing and loaner equipment options.

View the file

Other files for this federal contract opportunity

Other files attached to ROMO SERVICE & SUPPORT FOR AFMS, newest first.
File Type Posted
Wage_Determination_Per_SCA_2015-5421_Rev__33_May_13__2026.pdf PDF
Price_Schedule.xlsx XLSX spreadsheet
Sol_140P1226Q0040.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Statement of Work

Rocky Mountain National Park (ROMO) Automated Fee Machines

Service, Support, and Maintenance

Description of Equipment, Software, and Connectivity by Location

AFM Equipment and Software Overview

See Section 1.2 AFM Connectivity and Programming by Location for a description of each location, its surrounding area and connectivity availability.

Current automated fee machines operating at Rocky Mountain National Park:

AFM Location and Descriptions

1. Beaver Meadows Entrance Station Lane 1 Machine Description: VenTek M600 AIO CORE MACHINE W/WRAP, 16-2130 DOOR Kiosk Model: 00-730-02 Power Supply: AC Power Cabinet Dimensions: 34” x 25” x 17”

2. Beaver Meadows Entrance Station Lane 2 Machine Description: VenTek M600 AIO CORE MACHINE W/WRAP, 16-2130 DOOR Kiosk Model: 00-730-02 Power Supply: AC Power Cabinet Dimensions: 34” x 25” x 17”

3. Beaver Meadows Entrance Station Lane 3 Machine Description: VenTek M600 AIO CORE MACHINE W/WRAP, 16-2130 DOOR Kiosk Model: 00-730-02 Power Supply: AC Power Cabinet Dimensions: 34” x 25” x 17”

4. Fall River Entrance Station Lane 1 Machine Description: VenTek M600 AIO CORE MACHINE W/WRAP, 16-2130 DOOR Kiosk Model: 00-730-02 Power Supply: AC Power Cabinet Dimensions: 34” x 25” x 17”

5. Fall River Entrance Station Lane 2 Machine Description: VenTek M600 AIO CORE MACHINE W/WRAP, 16-2130 DOOR Kiosk Model: 00-730-02 Power Supply: AC Power Cabinet Dimensions: 34” x 25” x 17”

6. Fall River Entrance Station Lane 3 Machine Description: VenTek M600 AIO CORE MACHINE W/WRAP, 16-2130 DOOR Kiosk Model: 00-730-02 Power Supply: AC Power Cabinet Dimensions: 34” x 25” x 17”

7. Grand Lake Entrance Station Lane 1 Machine Description: VenTek M600 AIO CORE MACHINE W/WRAP, 16-2130 DOOR Kiosk Model: 00-730-02 Power Supply: AC Power Cabinet Dimensions: 34” x 25” x 17”

8. Grand Lake Entrance Station Lane 2 Machine Description: VenTek M600 AIO CORE MACHINE W/WRAP, 16-2130 DOOR Kiosk Model: 00-730-02 Power Supply: AC Power Cabinet Dimensions: 34” x 25” x 17”

9. Wild Basin Entrance Station Machine Description: VenTek M600 AIO CORE MACHINE W/WRAP, 16-2130 DOOR Kiosk Model: 00-730-02 Power Supply: AC Power Cabinet Dimensions: 34” x 25” x 17”

10. Lily Lake Trailhead Machine Description: VenTek M600 AIO CORE MACHINE W/WRAP, 16-2130 DOOR Kiosk Model: 00-730-02 Power Supply: Solar Cabinet Dimensions: 34” x 25” x 17”

11. Lumpy Ridge Trailhead Machine Description: VenTek M600 AIO CORE MACHINE W/WRAP, 16-2130 DOOR Kiosk Model: 00-730-02 Power Supply: Solar Cabinet Dimensions: 34” x 25” x 17”

AFM Connectivity and Programming by Location

Refer to the Table below for names of the AFM sites and connectivity options available.

Some locations may have multiple connectivity options and others may have only intermittent connectivity. The contractor must outline how sites will maintain accountability and accuracy of sales transactions during connectivity disruptions.

If a wireless cellular signal is available as the Primary Connectivity, or the contractor wants to propose using it if it is the Secondary, the contractor must acquire the service and manage the contract for this connectivity.

Table 1: AFM Connectivity and Programming by Location chart:

Location Name Primary Connectivity

Secondary Connectivity

Type of programming:

See Sections 6.3 Quick-Pick/

6.4 Pay-by-Space

Comments

Beaver Meadows Entrance Station Lane 1

Wireless Cellular N/A Quick-Pick AT&T or Verizon

Beaver Meadows Entrance Station Lane 2

Wireless Cellular N/A Quick-Pick AT&T or Verizon

Beaver Meadows Entrance Station Lane 3

Wireless Cellular N/A Quick-Pick AT&T or Verizon

Fall River

Wireless Cellular N/A Quick-Pick & Pay-by- Space

AT&T or Verizon

Fall River Entrance Station Lane 2

Wireless Cellular N/A Quick-Pick AT&T or Verizon

Fall River Entrance Station Lane 3

Grand Lake

Grand Lake

Lane 2

Wild Basin

Satellite N/A Quick-Pick N/A

Lily Lake Trailhead Wireless Cellular N/A Quick-Pick AT&T or Verizon Lumpy Ridge Trailhead

Network Connectivity Diagram or Park Map

Software Licensing

Software purchased by the government is owned by the government. The contractor must identify all licensing requirements applicable to the hardware or software, including, but is not limited to the following:

• Applicable license renewal requirements and procedures.

• Number of users allowed and associated fees; user set up and registration, change process, limitations (e.g., use on all government computers or limited), etc.

• Other fees (e.g., transactional, monthly or annual fees for the use of software such as in Software-as-a-Service (SaaS) where the software is remotely hosted and accessed as a Web-based service).

• New releases and/or upgrades to software or firmware fees (include details about procedures for minor release to fix bugs and major release with new features; frequency of releases/upgrades).

Services and Deliverables Provided by Contractor

The contractor must provide services to ensure the equipment and/or software is operational according to the functional and compliance requirements of this SOW. Examples of services may include but are not limited to: Configuration, training, operation manuals and related documents, service level agreement (SLA) and technical support, repairs and warranty terms, and system administration. In order to provide these services, the contractor must:

• Adhere to IT Security requirements; see Appendix-IT and Security Requirements.

• Maintain all payment application devices, software, and/or hardware included in the Cardholder Data Environment (CDE) and supported by this contract in accordance with the PA-DSS Implementation Guide for credit card application devices.

The contractor will not be granted DOI NPS network access to provide direct support for the installation, technical support or system administration of the solution. The Contractor must support an authorized NPS employee who will perform these functions based on guidance received by the contractor. The contractor must describe if the NPS employee must be an IT Specialist, otherwise it should be assume the employee is not an IT Specialist.

Configuration and Support Services

Configuration and Support Services Plan

The contractor must gather information from the park and provide configuration and support services plan that includes the following considerations:

• Infrastructure, connectivity and communications (if applicable) options and power availability that must be provided by the park.

• List of all peripherals and supplies required by the park to have on hand for the continue operations (e.g., receipt paper, surge protectors, etc.)

• Detailed network description and/or diagram of equipment and software with names, locations, type of connectivity and IP addresses (if applicable and known).

• Milestone dates and tasks for configuring, testing, installing, training, and implementing.

• Logistics needed from NPS for configuration, support, services and staff training:

o Location and positioning of the equipment to minimize environmental impacts and other obstacles that could impede successful use of the machine (e.g., glare, direct sunlight, driving rain, hail, sand, prevailing winds, etc.).

o Timing considerations for installation (e.g., during park hours, before park opens, after park closes, etc.).

o Access to NPS buildings and/or computers requiring an NPS escort or NPS staff with elevated computer permissions (e.g. IT Specialist with administrative rights to install software).

o Travel time, road conditions/closures, seasonal traffic, etc. to/from/between installations (e.g., congestion, periods of high visitation, inclement weather, distances, etc.).

o Contact numbers for NPS staff, collection locations, main switchboard, etc.

o Communication constraints (e.g., cell phone reception).

o Training, planning and logistics facility with adequate Internet connection, audio visual equipment support, access, size, etc.

Maintenance support and services The contractor must support and service equipment and software at the locations described in Section

1.2 AFM Connectivity and Programming by Location.

The contractor must support and service equipment, software and configure the software per Section 13 Credit Card Compliance, Processing, and Programming and 1.0

The contractor must also test data transfer and sales activity processing, and successful card authorization and settle complete the following:

2.1.2.1 Testing of Configuration

The contractor must configure the equipment and software, test the configuration and verify accurate sales of products, receipt generation, data transfer and sales activity processing, including transaction authorizations and settlement, prior to operation. This test must be coordinated with the park’s installation point of contact.

The contractor must perform a test in the production environment before the unit is put into operation to ensure the credit card merchant account authorization and settlement is correct.

The Contractor must coordinate with the park POC to verify that the test funds reached the proper GL Revenue Account in the NPS Accounting Operations Center (AOC) daily summary report of credit card deposits prior to live credit card sales being performed.

2.1.2.2 Support and Service According to PA-DSS Implementation Guide

The contractor must service payment systems in accordance with the PA-DSS Implementation Guide for the payment application device and must deliver:

• The PA-DSS Implementation Guide for the credit card payment application installed in the equipment or software.

• Documentation attesting and verifying that configurations and installations have been performed according to the PA-DSS Implementation Guide.

Manuals and Documentation

Updated Manuals and Documentation

Within 30 days of any software or hardware update or new release, the contractor must provide the park with an updated user manual (electronic format) describing operational and technical changes. If the change is minor, a technical bulletin will be acceptable.

SLA and Technical Support

The contractor must provide technical support for the equipment and software to keep it operational with minimal down-time. The contractor must describe the technical support in writing in the form of a Service Level Agreement (SLA).

Service Level Agreement (SLA)

Items to be included in the technical support SLA:

• Support Mode: Methods by which users may access and receive assistance/service.

• Service Availability: Days and times when technical support will be available.

• Time Limit for Call Waiting: Average and maximum times that users may have to wait before speaking with a Support Representative.

• License Renewal Process: Timing and process for license renewal (if applicable).

• Access to Configurations: Methods by which contractor’s technical support team will access the park’s AFM(s) and software application to provide remote support.

• Patch Deployment Time: Verification that critical security patches will be deployed no more than one month from patch release, in accordance with PCI DSS Requirement 6.1.

• Hardware Repair: Options, availability and expected arrival time for hardware repairs, loaner parts, and spare parts to be received and operational at the park.

• Issue Resolution Time: Average and maximum times between report of a problem and resolution.

Help Desk Support Modes

The contractor must provide helpdesk support at minimum through the following modes: telephone and email.

Technical Support Days and Hours of Service

The contractor must provide technical support that meets the following minimum service level requirements:

The contractor must provide, at minimum, unlimited remote support seven (7) days a week (including federal holidays), from 8:00 AM - 8:00 PM Eastern Time.

Urgent Technical Support Requests

The contractor must provide urgent* technical support to users according to the following minimum parameters:

• Response Time: 30 minutes for initial acknowledgement of the technical support request.

• Proposed Resolution Time: Resolution of the issue within two (2) hours, 95% of the time, unless it requires the shipment of a replacement part which must be shipped according to the contractor’s SLA.

*Urgent defined: Technical Support request conditions when one or more registers, printers, or card readers that are down at a location without an alternative or backup unit.

Normal Technical Support Requests

Contractor must resolve normal* technical support requests within the following parameters:

• Response Time: Two (2) hours for initial acknowledgement of the technical support request

• Resolution Time: Resolution of issue within four (4) days, 95% of the time.

*Normal Technical support requests may include, but are not limited to:

• Responding to questions about usage of the system

• Providing technical support to a NPS non-technical employee to troubleshoot and repair equipment

• Direct database manipulation or repair

• Modifying existing or adding new items/products

• Upgrade of software licenses

• Fixing or providing a workaround software bugs

• Diagnosing and resolving communications issues between the equipment, software, and any connections like the NPS designated processing bank

• Diagnosing and resolving credit card payment processing issues

• Fixing reporting errors

Report of Technical Support

The contractor must deliver within ten (10) business days following the end of a quarter*, a help desk summary report for the previous quarter’s help desk activities.

The report must be formatted to print either Letter or Legal size, with title of document and date created in header, page count in “page 1 of #” format in footer. If the contractor provides the park point of contact (POC) access to an online help desk system with the required information a report submission is not necessary.

The report must include at minimum the following information:

• Date and time support, requested including hardware repairs and software upgrades.

• Short title to describe the nature of the support request.

• Name of person submitting request.

• Outstanding support requests by priority.

• Time to resolution for each support request.

• Resolutions outside of the allowable limits, per the SLA.

*Quarters defined: Qtr1-October through December; Qtr2-January thru March; Qtr3-April through June; Qtr4-July through September.

Remote Technical Support

The contractor must provide remote technical support to a NPS employee who can perform non-technical tasks. The contractor’s technician may also access the equipment or software as long as they are compliant with the contractor access requirements described in Appendix-IT and Security Requirements.

Onsite Technical Support

If troubleshooting remotely does not resolve the hardware or software issue and the issue is not covered by the products warranty or contractors SLA, the contractor must provide an option for the government to procure onsite technical support through a contract modification, section 6.6 Travel applies to this requirement.

Hardware Repairs

Hardware Repairs

As part of the warranty, the contractor must perform remote troubleshooting of hardware supported under this SOW by guiding a NPS employee through performance of non-technical tasks with the equipment.

The contractor must describe the necessary tools for NPS employees to have on hand in order to perform the troubleshooting or repairs. If specialized tools are necessary, the contractor must provide them in a toolkit with the delivery of the AFM.

If remote technical support does not resolve the problem and the problem is not covered under the warranty the park may ship, at the park’s expense, the hardware to the contractor for repair.

Prior to initiating the repair and as part of the services provided in this SOW, the contractor must provide a description of repair needed, including the costs and estimated time of the repair of any parts that are out of warranty. The parts may either be ordered through a contract modification or purchased under the micro purchase authority based on the price list included in the contracts bid schedule.

Return Material Authorization (RMA)

The contractor must provide a description of their Return Material Authorization (RMA) process for the repair of hardware under warranty.

Loaner Parts needed during Hardware Repairs

The contractor must provide an option in their SLA for the park to purchase loaner parts or equipment while the park’s part or equipment is under repair. The SLA must address how quickly the loaner parts may be expected to be available and shipped to the park.

Spare Parts as needed for servicing, warranty, or replacement/loaner parts.

The contractor must provide a spare parts price list with the bid schedule which the park may purchase in order to make an emergency repair. The spare parts price list may be used for replacing parts during repairs of hardware that are out of warranty or to have on hand for immediate use. The spare parts price list should include individual and packages of the most common spare parts. Remanufactured parts must be indicated on the bid sheet for parts.

As part of Section 2.3.1 Service Level Agreement (SLA) and 2.4.1 Hardware Repairs, the contractor must provide remote technical support to the park POC who will install the spare part.

Destruction of Storage Devices

If any data storage device is removed from the AFM and is not reinstalled in the NPS AFM, the contractor must provide the NPS with certification that the data storage device was destroyed per guidelines in Draft NIST Special Publication 800-88 Revision 1, September 2012 or later.

Managed Services (PCI)

PCI DSS is a multifaceted security standard that includes requirements for security management, policies, procedures, network architecture, software design and other critical protective measures. This comprehensive standard is intended to help organizations proactively protect customer account data.

For requirements related to PCI DSS see Section 3.1 Credit Card Compliance. More information can be found at https://www.pcisecuritystandards.org/.

Managed System Administration Services

Unless the contractor proposes to implement a P2PE solution per section 3.1.7 P2PE PTS 3.X Payment Device Hardware Encryption, the contractor must provide managed system administration in compliance with the PCI Data Security Standard (DSS).

Managed system administration services are defined as:

• Maintenance of firewall configuration on the deployed solution to prevent unauthorized access (DSS Requirement 1)

• Initial and ongoing configuration management and hardening of the underlying operating system (DSS Requirement 2)

• Regular updates to antivirus software (DSS Requirement 5)

• Updates and patching of operating system and critical software (DSS Requirement 6. 1)

• Logical access control, user account management, password and account lockout management and management of access control lists (DSS Requirements 7 and 8)

• Secure, remote access using two-factor authentication (DSS Requirement 8.3)

• Monitoring server security and reporting incidents (DSS Requirement 10)

• Vulnerability scanning and management – from within the network on which the equipment or software sits only (DSS Requirement 11.2)

• Host intrusion detection/prevention (DSS Requirement 11.4)

• File integrity monitoring (DSS Requirement 11.5)

Required Managed Services for Merchant PCI Compliance

The managed system administration services requirements in this solicitation will depend on the method by which the card processing payment devices or software will connect to the Internet. See Appendix- Connectivity Description for a description of the different types of connectivity.

The Managed Services for Merchant PCI Compliance table below shows managed services in each row;

the columns represent the various connectivity options. The contractor must perform the Managed Services based on the connectivity implemented at each location, as described in Section 2.2 Connectivity and Programming by Location, for the fields labeled as “Required by Contractor”. For example, maintenance of the firewall configuration on the network providing connectivity to the unit is required under this contract if the unit is connected via Commercial ISP but not if directly connected to the NPS Enterprise Service Network (ESN).

https://www.pcisecuritystandards.org/

Validation of Managed Service Providers for Merchant PCI DSS Compliance

The contractor must achieve and maintain PCI DSS compliance for all of the managed services they are providing in accordance with the current version of PCI DSS published by the PCI Security Standards Council.

Annually, the contractor must provide validation of PCI compliance in the form of:

• A current Attestation of Compliance (AOC) that verifies compliance with the PCI DSS and,

• The executive summary from the Report on Compliance (ROC) or, Managed Services for Merchant PCI Compliance

DSS

Requirem ent

P2PE

PTS 3.x

Wireless Cellular

Direct ESN VSAT

ESN

Commerci al ISP

Hardware

(L2L) VPN

Analog Only

No Connectio n Maintenance of firewall configuration on the deployed solution to prevent unauthorized access

1 Not Applicable

Required by

Contractor

Performed by NPS

Performed by NPS

Required by

Contractor

Performed by NPS

Not Applicable

Not Applicable

Initial and ongoing configuration management and hardening of the underlying operating system

2 Not Applicable

Required by

Contractor

Required by

Contractor

Required by

Contractor

Required by

Contractor

Required by

Contractor

Required by

Contractor

Not Applicable

Update of antivirus software (DSS Requirement 5)

5 Not Applicable

Required by

Contractor

Required by

Contractor

Required by

Contractor

Required by

Contractor

Required by

Contractor

Not Required

Not Applicable

Updates and patching of operating system and other critical software (DSS Requirement 6.1)

6.1 Not

Applicable

Required by

Contractor

Required by

Contractor

Required by

Contractor

Required by

Contractor

Required by

Contractor

Required by

Contractor

Not Applicable

Logical access control, user account management, password and account lockout management and management of access control lists (DSS Requirements 7 and 8)

7,8 Not Applicable

Required by

Contractor

Required by

Contractor

Required by

Contractor

Required by

Contractor

Required by

Contractor

Required by

Contractor

Performed by NPS

Secure remote access using two-factor authentication (DSS Requirement 8.3)

8.3 Not

Applicable

Required by

Contractor

Required by

Contractor

Required by

Contractor

Required by

Contractor

Required by

Contractor

Required by

Contractor

Not Applicable

Monitoring of server security and incident reporting (DSS Requirement 10)

10 Not Applicable

Required by

Contractor

Performed by NPS

Performed by NPS

Required by

Contractor

Performed by NPS

Required by

Contractor

Not Applicable

Vulnerability scanning and management – internal only(DSS Requirement 11.2)

11.2 Not

Applicable

Required by

Contractor

Performed by NPS

Performed by NPS

Required by

Contractor

Performed by NPS

Required by

Contractor

Not Applicable

Host intrusion detection/prevention (DSS Requirement 11.4)

11.4 Not

Applicable

Required by

Contractor

Performed by NPS

Performed by NPS

Required by

Contractor

Performed by NPS

Required by

Contractor

Not Applicable

File integrity monitoring (DSS Requirement 11.5)

11.5 Not

Applicable

Required by

Contractor

Required by

Contractor

Required by

Contractor

Required by

Contractor

Performed by NPS

Required by

Contractor

Not Applicable

• A statement from a PCI Qualified Security Assessor (QSA) which certifies the scope of services covered by their annual assessment and states that the contractor’s AOC includes all relevant services related to their contract with the NPS.

The contractor must provide with their proposal either (a) the above documentation or (b) a statement that the contractor will provide the above documentation within three months of the award of the contract.

PCI DSS Compliance for Managed Services

PCI Managed Service providers must be on the Visa Global Registry of Service Provider, see Validation of Managed Service Providers and 4.1.9 PCI Data Protection Addendum Contract for more details.

Service Providers

Service providers used to store or manage NPS credit cardholder data must be registered through the Visa Global Registry of Service Providers as a validated Level 1 Service Provider.

PCI Data Protection Addendum

Upon award of a contract for this SOW, the contractor must sign the Attachment: PCI Data Protection Addendum.

Report of Managed Services

The contractor must deliver a summary report for the previous quarter’s system administration activities within 10 business days of end of each quarter. This report must include all:

• System configuration changes

• Patches applied

• Vulnerabilities and the remediation performed

• Data recovery activities

Software Restoration and Backup Services

If ordered on the contract, the contractor must perform additional services of restoring or migrating software to a new location.

If the contractor requires a park employee to assist, the contractor must notify the park what information is needed to conduct the restoration or migration. This includes specifying the park resources needed (e.g. scheduling specific time with the park employee(s) such as Park IT Specialists and identifying the time needed to complete the restoration or migration).

Software Restoration

If ordered on the contract, the contractor must restore the software after a computer/server failure.

Restoration includes but is not limited to:

• Restoring park-specific configuration files and equipment programming and, http://www.visa.com/splisting/index.html

• Restoring recoverable transactional data files, and

• Restoring equipment communications.

Software Configuration Back-up

The contractor must provide a current copy of the hardware and software system configuration as a back-up for restoration in case of equipment failure.

The contractor must either maintain the backup themselves or provide a written process for the park to maintain the back-up.

Notification and Scheduling

If the contractor requires a park employee to assist with any upgrade or relicensing, the contractor must schedule at least 14 calendar days in advance.

The contractor must communicate to the park employee what information is needed, how much time installations or upgrades will take, and whether specialists (e.g., Park IT Specialists) are required in order to complete the upgrade or relicensing.

Upgrades to Current Versions of Software

The contractor must upgrade all equipment, payment applications, and back-office applications with the most current version of software or firmware available. The Contractor must notify the park within thirty (30) days of notification of software upgrades for any purchased equipment. Applicable upgrades must be implemented by the contractor within ninety (90) days. Available upgrades that address security vulnerabilities must be implemented by the contractor within thirty (30) days.

Credit Card Compliance, Processing, and Programming

Credit Card Compliance

Processing and Certification with Treasury-Designated Payment Processor

US Treasury regulation (TFM 8060.20) requires all credit card transactions collected by or on behalf of the government be deposited directly into a US Treasury NPS designated account through the Treasury’s Financial Management Services (FMS) Card Acquiring Service (CAS).

The contractor’s payment application software or device for processing credit card payments must be certified with the Treasury-designated payment processor (currently Vantiv’s Tandem processing platform).

http://fms.treas.gov/cas/index.html

Comply with FMS and Card Brand Card Processing Rules and Regulations

All card processing must follow the US Treasury Financial Manual (TFM) Part 5 – Chapter 7000: Credit and Debit Card Collection Transactions and individual Card Brand Operating Regulations and Mandates.

The contractor must comply with any applicable rules and mandates in these regulations and mandates.

Accepted Card Brands

The payment application software must be able to process visitor tenders of the Treasury designated credit card brands (Visa, MasterCard, Discover, American Express, Diners Club International, JCB, and China Union Pay). The payment application devices must be able to be modified to match any changes to the credit card brand options made by Treasury.

PA-DSS Contract Requirements for Hardware/Software

The Payment Application Data Security Standards (PA-DSS) identifies the security controls with which the proposed solution must comply and ensures a payment application can be deployed in a way that will not negatively impact a merchant’s PCI DSS compliance. The contractor must ensure that any credit card payment application version used in processing NPS cardholder data is a current, PA-DSS validated payment application.

3.1.4.1 PA-DSS Validation Requirement

The PCI-DSS identifies the Payment Applications Data Security Standards (PA-DSS), security controls with which a payment application must comply. The contractor must ensure that any credit card payment application version used in processing NPS cardholder data is a current PA-DSS validated payment application. PA-DSS validation is specific to a payment application version number and includes a revalidation date and an expiration date.

The contractor must provide the specific name and version number of their payment application, and must demonstrate that this name and version number have been validated as PA-DSS compliant.

Refer to the database of Validated Payment Applications for details.

3.1.4.2 PA-DSS Implementation Guide Requirement

The contractor must ensure that the payment application is deployed in accordance with the instructions detailed in the PA-DSS Implementation Guide for the specific product suite and version that is associated with its PA-DSS validation.

The contractor must include the PA-DSS Implementation Guide as part of their proposal, and must ensure that the document includes appropriate proprietary markings.

EMV Chip and PIN Technology - Compatible and Configured

Executive Order 13681 (EO, Improving Security of Consumer Financial Transactions, dated October 17, 2014, require all new or replacement credit card processing devices to support (EMV-capable) Europay, http://fms.treas.gov/cas/rules.html http://fms.treas.gov/cas/rules.html https://www.pcisecuritystandards.org/approved_companies_providers/vpa_agreement.php https://www.whitehouse.gov/the-press-office/2014/10/17/executive-order-improving-security-consumer-financial-transactions

MasterCard and Visa (EMV) Chip and PIN processing. The list of approved EMV compatible products is available on the EMVco Approved Devices website.

3.1.5.1 EMV Chip and Pin Compatible

The AFM must be delivered with the credit card payment devices capable of supporting EMV chip and PIN processing (potentially requiring a software upgrade) upon delivery.

3.1.5.2 EMV Chip and Pin Configured and Functional

The contractor must ensure the credit card payment devices are deployed to support chip and PIN transactions (including any certification by the Treasury-designated payment processor).

The contractor must support the parks during the transition to chip and PIN processing, and must provide instructions to the park on any changes in usage or operating procedures.

Accept Near Field Communication (NFC) Payments

The payment device must also support Near Field Communications (NFC) for contactless payments, supporting at minimum Apple Pay and Google Wallet before or when the EMV Chip and PIN processing is configured and functional.

P2PE PTS 3.X Payment Device Hardware Encryption

Any payment devices that accept credit cards and communicate over an IP/SSL connection, including satellite or commercial DSL, must be compatible with the PCI PIN Transaction Security (PTS) 3.X standard and be deployed as part of a Point to Point Encryption (P2PE) solution supported by Vantiv.

The contractor must propose, configure, and install P2PE PTS 3.x credit card payment application device at each AFM which communicates using an IP connection.

NOTE: The contractor may propose to NOT implement this requirement and instead provide the services required under Section 3.6 System Administration (Managed Services) for the implemented connectivity.

3.1.7.1 P2PE Encryption and Processing per Transaction Fees

The contractor must include the encryption and/or transaction fees charged by the encryption provider, which may be a 3rd party gateway provider, supported by the Treasury designated bank Vantiv.

http://www.emvco.com/approvals.aspx?id=83

Below is a monthly transaction estimate based on the last year of available information.

Month Calendar Yr Estimate of Credit Card Transactions

January 2026 725 February 2026 712 March 2026 1419 April 2025 651 May 2025 1081 June 2025 1147 July 2025 1468 August 2025 1925 September 2025 2242 October 2025 169* November 2025 660 December 2025 1540 Total 13739

*Quantities for October were impacted by the 2025 government shutdown, anticipate numbers closer to September quantities.

3.1.7.2 Magnetic Credit Card Readers

If IP/SSL is used for connectivity, any magnetic strip reader (MSR) as part of the equipment solution must be PTS 3.x validated or they must be deactivated from reading the Cardholder Data Primary Account Number (PAN) and/or the Sensitive Authentication Data (SAD).

Credit Card Processing

Credit Card Authorization

The payment application solution must be able to obtain a credit card authorization and print a receipt in a pre-determined amount of time, set by the system administrator (i.e., 60 seconds for a dial-up, analog connection or 5 seconds for an IP connection). If this threshold is exceeded, the payment application must force the transaction and obtain authorization upon connection.

The AFM should allow the same credit card to be used more than once on the same day at any one machine and for the same dollar amount. This occurs when a visitor is purchasing a variety of pass or permit types that may have varying expiration dates.

If the AFM cannot be programmed to allow the same credit card to be used more than once in a day, it must allow payment for multiple products as a single transaction but print separate receipts for each product/item with the relevant expiration dates. For example, a visitor pays for a campsite for 4 days and a 1-day boat permit during a single transaction. The visitor’s total would reflect the sum due for the campsite and the boat permit, but s/he would receive individual receipts for the campsite and the boat permit, showing the appropriate expiration date for each.

Intermittent / Offline Store and Forward

When connectivity is intermittent or offline for an unexpected reason and communications are not available for card authorization-after a designated period of time (e.g. 15 seconds for IP and 60 seconds for dial-up connections), the payment application solution must securely (according to PCI DSS Standards) capture, process, store and forward the authorization request as soon as the network connection to the authorizing bank is reestablished.

All transactions stored in the offline mode and then rejected must be documented and included in a report to the NPS.

Cardholder Data Storage

No cardholder data may be stored in the machine, even if encrypted, after authorization or after settlement of any transaction.

Credit Card Programming

Merchant ID Account (MID)

The payment application device or software must use a Merchant ID (MID) account obtained from the US Treasury’s Fiscal Services- designated processor and its platform for each collection location.

The contractor must provide the name of the PA-DSS Validated payment application software that will be handling the credit card authorization and settlement.

Upon award for implementation, the contractor must provide any additional information necessary for the Park POC to submit the application to create the MID account.

Terminal ID (TID) and Terminal Number (TIN) for MID

The contractor must program the payment application to ensure each AFM has a unique Terminal ID (TID)/TIN associated with a MID. This is required for the NPS fee collection equipment inventory purposes.

The contractor must work with the park and Treasury’s processor (Vantiv) to determine when there should be unique merchant IDs (MIDs) for multiple AFM units versus allowing multiple AFM units to share a single MID with unique TID/TINs.

The contractor is responsible for properly programming and providing a report of the payment application devices and software with the correct MID and TID/TIN.

Test Equipment and MID

Contractors, in coordination with NPS park/site and Vantiv, must conduct test transactions to ensure that the equipment is properly programmed before the equipment is operational and available to accept cards from visitors.

Cardholder Data Security on Reports

Credit cardholder data must be masked on all reports. If the PAN is included in any report, no more than the first 6 digits and the last 4 digits may be printed. The card expiration date and CVV number must never print. The contractor must handle and process cardholder data per PCI DSS standards as well as any requirements of the Fair and Accurate Credit Transactions Act (FACTA).

Federal and IT Compliance Requirements

Federal IT Security and Network Access

Protecting the NPS network and the visitor information is a high priority and compliance with all relevant security policies is essential. The contractor must agree to adhere to all relevant security standards.

Any user accessing the NPS ESN through the software VPN must have and use current NPS active directory credentials and a Personal Identity Verification (PIV) card (“smart card”). If the contractor requires access to the DOI/NPS network to support the equipment or software, refer to the procedures and requirements in Appendix: IT and Security Requirements.

Section 508 of the Rehabilitation Act

In 1998, Congress amended the Rehabilitation Act of 1973 to require Federal agencies to make their electronic and information technology (EIT) accessible to people with disabilities. Inaccessible technology interferes with an ability to obtain and use information quickly and easily. Section 508 was enacted to eliminate barriers in information technology, open new opportunities for people with disabilities, and encourage development of technologies that will help achieve these goals. The law applies to all Federal agencies when they develop, procure, maintain, or use electronic and information technology. All EIT procured under this RFP, including [EQUIPMENT] units and software applications, must comply with the requirements of Section 508. Additional information about Section 508 compliance can be found at http://www.section508.gov.

The contractor must complete Attachment– AFM Section 508 Accessibility Requirements.docx for the applicable requirements. The contractor must indicate the compliance of the proposed solution as:

Fully, Partially, Not, or Don’t Know.

Americans Disabilities Act (ADA) Accessibility

The physical AFM must comply with the Americans Disabilities Act (ADA) accessibility requirements applicable to their design, user options and interfaces.

• All AFMs must be no more than 48 inches above ground to ensure customer operated controls are accessible.

http://www.section508.gov/

• More information on accessibility can be found at :

http://classicinside.nps.gov/documents/Basic_ADA_Accessibility_Guidelines_for_AFM%27s.pdf and http://www.access-board.gov/adaag/ADAAG.pdf

AFM Functional and Technical Equipment for Services and Support

Following are the functional requirements section defines the requirements that the AFM units must meet.

AFM Unit Basic Functional Requirements

The NPS uses terminology developed by the parking industry to describe choices or options available through an AFM. Two program options used by the NPS: “Quick-Pick” and “Pay-by-Space.” Refer to

2.2 AFM Connectivity and Programming by Location for the programming type for each machine.

Whichever program is selected, they must both meet the following basic requirements:

Ease of Transaction Processing

The AFM must have a user friendly interface to prompt the customer through the purchase process in a clear and timely manner (e.g., payment and tender options, instructions for exchanging the AFM receipt for the appropriate product (entrance pass, camping permit, etc.), other information as necessary.

Menu prompts should be simple, instructions clear, and ease of use intuitive.

Product Pricing

The AFM programming must be flexible to allow sales of multiple products at varying prices. Park staff with the appropriate user rights must have the ability to change pricing for each product. See Section

7.0 Products to Program for a draft of product pricing. The contractor must review and confirm the product pricing with the designated park POC.

Applying a Discount to a Product

The AFM programming must allow for a configurable discount function.

The specific business practice is for when the visitor owns an Interagency Senior or Access Passport, s/he qualifies for a 50% price discount on a specific product such as camping. The AFM should be programmed to:

• Prompt the visitor for the six (6) to nine (9) digit pass number associated with the discount.

• Calculate the appropriate price discount and prompt for payment that includes the discount.

• Allow the passport number entered must to be displayed on the receipt.

• Limit/restrict to not allow the Senior or Access Interagency pass number to be used for a discount for more than one product per transaction If feasible, the program should restrict the use of a specific number to one transaction for the duration of its use (for example, the discount will only apply to one campsite at a time for the duration of the visit).

• Park staff, with the appropriate user rights, must have the ability to change the discount percentage for each for each product.

http://classicinside.nps.gov/documents/Basic_ADA_Accessibility_Guidelines_for_AFM%27s.pdf http://www.access-board.gov/adaag/ADAAG.pdf

Multiply Price Charged by Quantity Entered

The AFM program must be configured to multiply the product by a quantity input by the visitor and then calculate the price for the total number of products and the payment due.

5.1.4.1 Apply specific question prompts for multiplying the rate

The AFM will prompt the visitor to enter the quantity for each product being purchased based on specific question prompts (e.g., “How many camping nights are you camping?” or “How many people?”

or “How many daily entrance fee receipts?”). See section 7.0 Products to Program for the specific questions per rate.

Calculate Expiration Date & Time for Valid Thru Date

The AFM program must calculate and display the expiration date on the receipt based on the following:

• Number of days valid – the expiration date is calculated based on the number of days or months the product can be used beginning with the sale date and the appropriate validity period for the specific pass. (i.e., Daily passes expire at sundown on the date sold; Weekly pass is valid for up to 7 days including the date of purchase; at the end of the twelfth month of the month it was purchased).

• Rate Multiplier: the expiration date is calculated based on the quantity days the visitor chooses to purchase (i.e., camping nights x number of days up to the maximum allowed).

• Set expiration date: the expiration date is calculated based on a pre-determined, specific date

• No expiration date: the product does not have expiration date (i.e., Interagency Senior and Access passports are valid for the owner’s lifetime).

The park staff, with the appropriate user rights, must be able to change the expiration date and time for each product.

Entry of Data based on Question Prompt

The AFM programming must allow the entry of alpha numeric data to a question prompt (i.e., number of people in the vehicle, the selected campsite number, Fee Notice Payment number, etc.)

Tender Processing

The contractor must program the AFM to accept the following tenders for payment:

5.1.7.1 Acceptance of Credit Card for Tender

The AFM programmed according to Sections 2.5 Managed Services (PCI), 3.0Credit Card Compliance, Processing, and Programming, and 3.0 Credit Card Compliance, Processing, and Programming.

Credit cards will be the only form of tender accepted.

Receipts configuration

AFMs must be programmed to not allow duplicate receipts to print unless configured to print two receipts (e.g. one for the visitor’s payment records and one for providing to the NPS in exchange for an Interagency Pass or posting at the specific campsite). See section 7.0 Products to Program for the specific receipt configuration per product.

AFM receipt printers must have the option to print or not print a receipt based on administrator preferences for the product. The no print option is used for re-entry items (e.g. someone with an annual pass which covers the entrance fee) where a receipt is not necessary to be printed.

The park staff, with the appropriate user rights, must be able to change the number of receipts to print for each product.

Printed Receipts Transaction Information

All printed receipts must include the following information:

• Park specific header with park name and phone number (ability for park POC to modify fields)

• Unique machine identifier

• Date and time of transaction

• Unique transaction ID number

• Line item descriptor with name and price of each product and relevant sales information

• Multipliers used in the price calculation

• Pass number entered when price of item is discounted

• Total of all transactional lines for receipt total

• Tender type used; Amount of change paid for cash tenders (if enabled)

• Truncated credit card account data on visitor receipts, merchant receipts, and journal tapes.

Only the last 4 digits of the PAN may be printed on receipts and journal tapes; expiration date should never print

• Print the valid through date in large font: “Month, Day, Year” and other specific validity information as applicable (e.g., Expires at sundown on {month, day, year}.

• Print variable data relevant to product (e.g., campsite number)

• Variable message in footer portion of receipt (minimum of 5 lines)

See Section 5.5.8 Receipt Paper for those requirements.

Out of Receipt Paper

The AFM must not allow a transaction to be completed if the printer is out of paper or in the event of a paper jam. Upon replacement or reloading of receipt paper, the AFM unit will print the receipt. The option to use a reprint transaction function is not an option for the NPS due to fraud potential. The AFM must be able to be programmed to send an alert notice when the machine is out of receipt paper or it is jammed, see Section 5.1.13 Alert notifications.

Transaction Data Capture

The AFM must capture and document for reporting all transactional data, including but not limited to:

• Unique machine identifier

• Date and time of transaction

• Unique transaction ID and number

• Product(s) sold

• Data entered by visitor in response to question prompts and statistical or memo data (e.g., people count, bus number, Fee Notice Number related to fee notice payments)

• Tender type used

• Amount paid

• Credit Card authorization number or decline message

Cancel or Abort Transaction

After a transaction has been initiated by the customer but prior to the tender being completed the visitor must be able to cancel (abort) a transaction. This action must not print a receipt.

Alert notifications

The AFM must have programming which allows alert notifications to be sent to a designated POC by email. The alerts are to notify the POC of any malfunctions such as out of paper or the door is open;

when collections have been performed; coin dispensers are low, etc.

User Access Management

The AFM program must follow user access controls according to FISMA, DOI IT Security, and PCI DSS requirements including the following:

Create Authorized Users by Security Functions

The AFM must have the ability to create users so they can be identified and authenticated with a unique username and password. The following requirements apply:

• Users may only access functions that they have specifically been authorized to access. For example, a manager level, credentialed user could create, modify, terminate, or delete user accounts but a Fee Collector cannot.

• There must be a way to disable a user account so that any data associated with that account can be accessed but the user can no longer log in to the system.

• User accounts may not be deleted unless there are no transactions associated with the user account.

Generate list of authorized users

The AFM must be able to generate a list of users authorized to access the AFM.

Password requirements

The AFM must enforce the following minimum password requirements:

• Enforces minimum password complexity of 12 or more case-sensitive characters

• A minimum of one character from at least three of the following four categories: uppercase, lowercase, numeric, and special (non-alphanumeric);

• Enforces at least one changed character when new passwords are created;

• Encrypts passwords in storage and in transmission;

• Enforces password minimum and maximum lifetime restrictions of one day minimum and 60day maximum; and

• Prohibits password reuse for 24 generations.

The AFM must allow the user to change his/her password; the machine must log all changes.

Authentication and Tracking

The AFM must authenticate all users and track all activities to the user, location, and park level.

Authentication must include each user having a unique password to complete user login.

AFM Programming

“Quick-Pick” programming – Basic sales

Quick-Pick programming shows a list of products that can be selected for purchase through the AFM.

Products may include Single Entrance passes, Park-specific Annual Entrance Pass, Interagency Senior Pass, Tent campsite (without site management) etc. Specific products that are sold for a physical location such as a campsite or numbered parking space may have the additional Pay-by-Space programming. See Section 7.0 Products to Program for a sample list of products to program.

Reports

Reports must detail sales and collection transactions performed at each AFM. These reports are used for sales statistics and to show payment compliance of spaces sold, when the…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .