Compensation Market Pricing Software Solution

Closed Solicitation Posted

Solicitation number
2031JW19Q00052
Agency
Office of the Comptroller of the Currency Department of the Treasury
Responses due
Set-aside
No set-aside

Opportunity facts

NAICS code
519190 All Other Information Services
PSC
Not on record

Notice details come from SAM.gov. Updated .

Notice text

2 versions

Update #2 · Latest ·

The purpose of this amendment is to add Vendor Questions and Responses..

Update #1 ·

This is a combined synopsis/solicitation for commercial items prepared in accordance with the format in Subpart 12.6 as supplemented with additional information included in this notice. This announcement constitutes the only solicitation; proposals are being requested and a written solicitation will not be issued.

This is a Request for Quotation #2031JW19Q00052 for Compensation Market Pricing Software Services. The solicitation and incorporated provisions and clauses are those in effect through Federal Acquisition Circular 2019-01, January 22, 2019.


This is not a small business set-aside and any qualified offer may submit a quotation. The NAICS for this requirement is 519190 - All Other Information Services, Size Standard: $27.5M.


FAR 52.212-1 INSTRUCTIONS TO OFFERORS COMMERCIAL ITEMS - (OCT 2018), which is incorporated into the RFQ by reference, provides guidance on preparing and submitting quotes. Paragraph "(b) Submission of offers" of Clause 52.212-1 is replaced, in its entirety, by the guidance that follows in this section.


The Office of the Comptroller of the Currency (OCC), Office of Human Capital is in search of a robust system and support services for compensation market pricing. As the OCC continues to hire external candidates from both Financial Institutions Reform, Recovery, and Enforcement Act (FIRREA) agencies and private sector, in addition to the increased administratively determined pay increase (ADPI) requests alleging salary disparity, it is vital that the OCC has a market pricing system which ensures employee pay rates remain competitive and that we have access to standard, intuitive reports and salary surveys.


Scope of Work


OCC has a requirement for a qualified company to provide compensation market pricing, support services, reporting, and access to salary surveys. The selected vendor must provide access to the online system (the "system") that can meet the following mandatory minimum requirements:


a. The system shall have the ability to upload and download data by users.
b. The system shall have the ability to easily price jobs on an ad-hoc basis. Ad-hoc job matches shall be saved into the database and stored for future use.
c. The system shall have the ability to propose survey matches for new or proposed jobs.
d. The selected vendor shall load into the system all surveys purchased by the OCC from third parties.
e. The system shall have the ability to price a job with more than one set of pricing matches.
f. The system shall have the ability to allow the user to easily switch back and forth from year to year to view a specific job's pricing history.
g. The system shall have the ability to suggest matches (survey title and survey job description) from survey sources that are not in the user's database, enabling the user to consider purchasing the survey.
h. The system shall have the ability to search for survey matches from surveys not in the user's database by scope factors such as geography or type of industry.
i. The system shall track a user's progress as he or she participates in surveys, edits job matches, and performs analysis.
j. The system shall be Section 508 compliant.
k. The system shall be capable of handling and securing Personal Identifiable Information (PII).
l. The system shall allow the OCC's system administrator to manage user rights by adding, deleting, or modifying user rights, and setting/resetting user passwords.
m. The system shall have the ability to restrict view capabilities by segmenting data by the OCC's business units and divisions. The software must have the ability to restrict access to specific surveys for selected users.
n. The selected vendor shall provide online and phone support services.


Section 508 Compliance


The vendor must ensure all Electronic Information Technology (EIT) meets the applicable standards of Section 508 of the Rehabilitation Act of 1973, as amended. All documents, reports, or plans submitted must be suitable for sharing within the OCC Intranet by meeting "Web-based Intranet" standards. In addition, any software, web, or hardware proposed for acquisition or use within the scope of this service shall meet applicable standards. During selection of any proposed software, web, or hardware item, the vendor shall ensure full compliance to standards. Exceptions to this requirement are determined solely by OCC. Any proposed exception shall be presented to the OCC IT Accessibility Program for determination.


The following standards apply:
36 CFR 1194 - ICT Software
36 CFR 1194 - Web-based Internet and Intranet Information and Applications
36 CFR 1194 - Functional Performance Criteria


Deliverables


The selected vendor is responsible for the following deliverables:
a. Access to software for four users.
b. Implementation support to include training of compensation specialists who will act as liaison and coordinate uploads of data; training of all users; and consulting services during implementation.
c. Maintain annual survey mapping for major compensation surveys and others requested by the OCC.
d. Documentation of the vendor's ability to keep all data provided to it secure and confidential.


Commodity Service Provider Security and Privacy Vendor Deliverables


A. Solution Authorization Before Operations


1. External Service Providers. NIST Special Publication 800-53, Revision 4, Security and Privacy Controls for Federal Information Systems and Organizations (SP 800-53 Rev. 4, Section 2.5, EXTERNAL SERVICE PROVIDERS.


FISMA and OMB policies require that federal agencies using external service providers to process, store, or transmit federal information or operate information systems on behalf of the federal government, assure that such use meets the same security requirements that federal agencies are required to meet. Security requirements for external service providers including the security controls for external information systems are expressed in contracts or other formal agreements. Organizations are responsible and accountable for the information security risk incurred by the use of information system services provided by external providers. Such risk is addressed by incorporating the Risk Management Framework (RMF) as part of the terms and conditions of the contracts with external providers.


Organizations can require external providers to implement all steps in the RMF except the security authorization step, which remains an inherent federal responsibility directly linked to managing the information security risk related to the use of external information system services. Organizations can also require external providers to provide appropriate evidence to demonstrate that they have complied with the RMF in protecting federal information. Prior to the implementation of the Offeror's system or services, the OCC will provide an Authority to Operate (ATO) or Authority to Use (ATU), based on the findings of the OCC's analysis of the system or services IT security and privacy controls.


2. Statement of Standards Attestation Engagements (SSAE) 18 Requirements. The Offeror shall provide the OCC with a Statement on Standards for Attestation Engagements (SSAE) 18 System and Organization Controls (SOC) Type II Report on an annual basis for services provided. The preferred coverage period for the report is July 1 through June 30 with a bridge letter covering the three months to September 30. For any gaps in the fiscal year coverage period (October 1 - September 30), the OCC will work with the Offeror to complete the internal controls assessment by relying on the work performed by the Offeror's competent and objective internal audit function per Statement on Auditing Standards No. 128, Using the Work of Internal Auditors. The submission of the results of the SSAE-18 SOC Type II Report shall be by a date mutually agreed by the Offeror and the Contracting Officer's Representative (COR), as shared with the Contracting Officer. If a SOC Type II Report is not available, the Offeror shall submit a SOC Type I report instead. The OCC will expect delivery of the report within 60 days of the end of the engagement coverage period.


B. General Requirements


1. Location. The Offeror shall not host any portion of the information, data, information system, infrastructure, or environment in facilities outside the contiguous United States, Alaska, Hawaii, and other U.S. Territories. Information collected, used, stored, maintained, or otherwise processed by the Offeror in the performance of this contract shall be accessed, transferred, stored or processed only within the sole jurisdiction of the United States Federal Government.


The primary locations shall be the primary and backup data centers located within the sole jurisdiction of the United States Federal Government. In addition, the maintenance and support operations of Offeror's technology and information must take place, and originate from, within the United States.


2. Authorization to Use, Store, or Share Sensitive Information. The Offeror shall be responsible for properly protecting all information used, gathered, or developed as a result of work under this contract. The Offeror shall also protect all government data, equipment, etc. by treating the information as sensitive. All information about the systems, gathered or created under this contract shall be considered as Controlled but Unclassified (CUI) information. It is anticipated that this information will be gathered, created, and stored within the primary work location. If Offeror personnel must remove any information from the primary work area, they shall protect it to the same extent they would their proprietary data and/or company trade secrets. The use of any information that is subject to the Privacy Act will be utilized in full accordance with all rules of conduct as applicable to Privacy Act Information.


3. Deliverables. The deliverables in this contract will be considered sensitive and shall not be shared with any other organization without prior approval from the OCC CO.


4. Confidentiality. The Offeror agrees to assume responsibility for protecting the confidentiality of government records and data associated with this contract, which are not public information. Each Offeror or employee of the Offeror to whom information may be made available or disclosed shall be notified in writing by the Offeror that such information may be disclosed only for a purpose and to the extent authorized herein.


5. Customer Design Specifications. The Offeror shall provide detailed technical architecture specifications and design artifacts for any client-site (i.e., OCC-hosted) IT components related to the use of the Compensation Market Pricing Software solution. A summary of these requirements shall be provided in the Offeror's proposal. The Offeror shall also detail any actions required by OCC to enable installation, configuration, and use of the Compensation Market Pricing Software solution. Final architecture specifications and design artifacts shall show any interconnections to OCC and/or external components or system, as well as any supporting software used in the final OCC solution, and shall be provided within 60 days of contract award.


C. Configuration Management - Equipment Maintenance


The Offeror shall ensure that the system, once operational, is properly maintained and monitored, to include immediate response to critical security patches, routine maintenance windows to allow for system updates, and compliance with the defined configuration management and change control processes. All patches and system updates shall be properly tested in a development environment before being implemented in the production environment.


D. Compliance Reviews and Audits


The Offeror shall permit compliance reviews and audits under applicable laws to allow OCC to meet legal and compliance obligations and shall implement processes that allow visibility into the privacy and security controls employed and their effectiveness. The Offeror shall provide OCC or authorized designated officials logical and physical access to the Offeror's facilities, installations, technical capabilities, operations, records, and databases pertinent to this contract within seven (7) calendar days upon request for these purposes.


E. Data Protection


1. Data Encryption. Where encryption is required, as specified by the OCC, the Offeror shall ensure that encryption is established and maintained for data at rest and in transit for the duration of the contract. The encryption employed shall be equivalent to those approved in Federal Information Processing Standards (FIPS) Publication 140.


2. Data Separation. Unless otherwise directed by the OCC, any storage of data shall be contained within the resources allocated by the Offeror to support the OCC and may not be on systems that are shared with other commercial or government clients.


3. Need to Know. Sensitive information, data, and/or equipment will only be disclosed to authorized personnel on a Need-To-Know basis. The Offeror shall ensure that appropriate administrative, technical, and physical safeguards are established to ensure the security and confidentiality of this information, data, and/or equipment is properly protected.


4. Use of PII. The Offeror shall not use any Personally Identifiable Information (PII), E-mail Groups, Lists, or contract information for any purpose other than those activities necessary to the performance of this contract.


F. Incident Response - Notification


All Information Security Incidents, including those that potentially or actually cause the compromise of OCC information, must be reported in accordance with the requirements below, even if it is believed the incident may be limited, small, or insignificant. OCC will determine when an incident requires additional focus and attention.


Offeror employees must report all information security incidents to the OCC Cyber Defense Center (CDC) immediately (within 1 hour) after becoming aware of the incident, at: Computer.Security@occ.treas.gov, (202) 649-7930, regardless of day or time.


Offeror employees must provide any supplementary information or reports related to a previously reported incident directly to the OCC CDC; with the following text in the subject line of the email: "Supplementary Information/Report related to previously reported incident ## [insert number]."


Do NOT include any Sensitive Information in the subject or body of any e-mail. To transmit Sensitive Information, use FIPS 140-2 compliant encryption methods to protect Sensitive Information in attachments to email. Passwords must not be communicated in the same email as the attachment.


When notifying the OCC CDC, copy the Contracting Officer if possible or, if reporting by phone or Contracting Officer's email is not immediately available, contact the Contracting Officer immediately after reporting the incident to OCC CDC.


G. Information Ownership


1. Government Access. The government will retain unrestricted rights to government data. The OCC retains ownership of any user created/loaded data and applications hosted on Offeror's infrastructure, as well as maintains the right to request full copies of these at any time.


2. Removal of OCC Data. The Offeror acknowledges OCC's exclusive right of ownership of the information and is required to transfer or return (or delete) all agency data collected, processed, stored or maintained by Offeror on behalf of OCC upon termination of services, and shall provide written certification and supporting documentation attesting to the return or deletion of agency data collected, processed, maintained, or stored by the Offeror.


3. eDiscovery. The Offeror must ensure data preservation requirements (i.e., halt destruction and maintain data the Offeror may not otherwise have to maintain) related to litigation holds are met. The Offeror shall also ensure that metadata associated with litigation holds are preserved. Metadata is electronically-stored information that describes the history, tracking, or management of an electronic document. It is created automatically when a user creates, modifies, accesses, or takes other actions with respect to an electronic document. The Offeror must notify the OCC within 1-hour of any third-party request/demand for the OCC's data.


The Offeror shall provide immediate access to all government data and government-related data impacting government data for review or scan, or conduct of a forensic evaluation, and physical access to any Offeror facility with government data.


H. Security Controls


1. Authorization Boundary. The Offeror will work with the OCC to define a clearly demarcated security authorization boundary for the system supporting this contract.


2. Customer Responsibilities. The Offeror shall provide in its proposal response a detailed list of all customer responsibilities assigned to the OCC, as defined by the vendor or documented under each FedRAMP and/or agency ATO package to be leveraged in the solution (as applicable).


For each customer responsibility, the Offeror shall identify whether the Offeror will be addressing the responsibility under the contract in order to fully meet the requirements specified in this PWS, or whether the responsibility will be assigned to the OCC.



I. System Access - Government Right to Terminate Access


The OCC, at its discretion, may suspend or terminate the access to any systems and/or facilities when an information security incident or other electronic access violation, use or misuse issue gives cause for such action. The suspension or termination may last until such time as OCC determines that the situation has been corrected or no longer exists.


J. Supply Chain Risk Management


In accordance with Federal requirements, the OCC requires supply chain entities to implement necessary security safeguards to: (i) reduce the likelihood of unauthorized modifications at each stage in the supply chain; and (ii) protect information systems and information system components, prior to taking delivery of such systems/components. This control also applies to information system services.


1. Supply Chain Safeguards. The Offeror shall:


a. Implement security and privacy controls for development systems, development facilities, and external connections to development systems as necessary to ensure compliance with the laws, regulations, standards, and requirements.
b. Implement personnel screening processes over development personnel to ensure suitability in accordance with relevant standards and requirements.
c. Use of tamper-evident packaging during shipping/warehousing.
d. Avoid the purchase of custom configurations to reduce the risk of acquiring information systems, components, or products that have been corrupted via supply chain actions targeted at specific organizations.
e. Vet the processes and security practices of subordinate suppliers, critical information system components, and services.
f. Employ a diverse set of suppliers to limit the potential harm from any given supplier in the supply chain.
g. Implement contract language regarding the prohibition of tainted or counterfeit components.
h. Restrict purchases from specific suppliers or countries per requirements issued by the U.S. Department of Homeland Security (DHS) and/or Federal Acquisition Security Council, as these requirements pertain to the management of supply chain risk for Federal Agencies.
i. Use trusted/controlled distribution, delivery and warehousing options to reduce supply chain risk.


Commodity Service Provider Security and Privacy Vendor Deliverables


(a) eDeliverable: Statement on Standards for Attestation Engagements (SSAE) 18 SOC Type II report. The preferred coverage period for the report is July 1st through June 30th with a bridge letter covering the three months to September 30th.
Frequency: Annually
Due Date: 5 days from contract award date and annually thereafter


(b) eDeliverable: Final architecture specifications and design artifacts showing any interconnections to OCC and/or external components or system, as well as any supporting software used in the final OCC solution.
Frequency: Once
Due Date: 60 days from contract award date


(c) eDeliverable: Demarcated security authorization boundary for the system supporting this contact.
Frequency: Once
Due Date: Within 60 calendar days of contract award; annual updates required


Government Inspection/Acceptance Period
Government inspection and acceptance is in accordance with FAR 52.212-4(a).


Delivery/Period of Performance


Delivery of the software system shall occur within 15 days after Government's acceptance of implementation of the software system.


The period of performance includes the transitional period for inspection and acceptance of the security compliance for software package.
Transitional Period-Security Compliance of Software: July 1, 2019 - August 31, 2019
Base Year: September 1, 2019 thru August 31, 2020
Option Year 1: September 1, 2020 thru August 31, 2021
Option Year 2: September 1, 2021 thru August 31, 2022
Option Year 3: September 1, 2022 thru August 31, 2023
Option Year 4: September 1, 2023 thru August 31, 2024
CONTRACT LINE ITEM NUMBER (CLIN) STRUCTURE


Offerors shall provide pricing in accordance with the Contract Line Item Number (CLIN) structure or propose a pricing structure for their software solution that meets the Government's requirement. Please provide the End User License Agreement (EULA) with price quote.



0001 Compensation Market Pricing Software/Access for 4 End Users Cost:______
0002 Training on Compensation Market Pricing Software Cost:______


Total Cost of Base Year: ___________


1001 Option Year 1: Compensation Market Pricing Software Maintenance
Total Cost of Option Year 1: __________


2001 Option Year 2: Compensation Market Pricing Software Maintenance
Total Cost of Option Year 2: ___________


3001 Option Year 3: Compensation Market Pricing Software Maintenance
Total Cost of Option Year 3: _____________


4001 Option Year 4: Compensation Market Pricing Software Maintenance
Total Cost of Option Year 4: _____________




Total Cost (to include option year periods):_____________



QUOTATION SUBMISSION INSTRUCTIONS


The offeror shall examine and follow all instructions. Failure to comply with the instructions in any way may result in a determination that the quote will not be evaluated by the Government. This determination will be made at the sole discretion of the Contracting Officer. All material submitted should be directly pertinent to the requirements of this Request for Quote (RFQ). Extraneous narrative, elaborate brochures, uninformative "Public Relations" material and so forth, shall not be submitted. All pages of each part shall be appropriately numbered, and identified with the name of the offeror, the date, and the solicitation number to the extent practicable.


In responding to this RFQ, it is the offeror's responsibility to provide current, complete and accurate information in its quotation. If in reviewing the quote the Government identifies or otherwise learns that the provided quotation information is not accurate or misrepresents the offeror's status or capabilities, that information may be used by the Contracting Officer as part of the offeror's responsibility determination and could result in the offeror not being eligible for award.


Quotations that fail to address all RFQ requirements may be considered deficient or unacceptable and may be excluded from further evaluation.


The quote shall:


(1) Propose firm-fixed-prices for all CLINs specified in the RFQ.


(2) The system shall meet the OCC security compliance within 60 days after contract award.


(3) Not deviate from the Government's requirement, product descriptions and quantities.



52.212-2 EVALUATION-COMMERCIAL ITEMS (OCT 2014)


(a) The Government will award a contract resulting from this solicitation to the responsible offeror whose offer conforming to the solicitation will be most advantageous to the Government, price and other factors considered. The following factors shall be used to evaluate offers:


(a) Technical Capability
(b) Past Performance
(c) Price


Technical and past performance, when combined, are significantly more important than price.
(b) Options. The Government will evaluate offers for award purposes by adding the total price for all options to the total price for the basic requirement. The Government may determine that an offer is unacceptable if the option prices are significantly unbalanced. Evaluation of options shall not obligate the Government to exercise the option(s).


(c) A written notice of award or acceptance of an offer, mailed or otherwise furnished to the successful offeror within the time for acceptance specified in the offer, shall result in a binding contract without further action by either party. Before the offer's specified expiration time, the Government may accept an offer (or part of an offer), whether or not there are negotiations after its receipt, unless a written notice of withdrawal is received before award.
(End of provision)



52.212-3 OFFEROR REPRESENTATIONS AND CERTIFICATIONS-COMMERCIAL ITEMS (OCT 2018)


The offeror shall complete only paragraph (b) of this provision if the offeror has completed the annual representations and certification electronically in the system for Award Management (SAM). If the Offeror has not completed the annual representations and certifications electronically, the offeror shall complete only paragraphs (c) through (u) of this provision.


(b) (1) Annual Representations and Certifications. Any changes provided by the Offeror in paragraph (b)(2) of this provision do not automatically change the representations and certifications in SAM


(2) The offeror has completed the annual representations and certifications electronically in SAM accessed through http://www.sam.gov. After reviewing SAM information, the Offeror verifies by submission of this offer that the representations and certifications currently posted electronically at FAR 52.212-3, Offeror Representations and Certifications-Commercial Items, have been entered or updated in the last 12 months, are current, accurate, complete, and applicable to this solicitation (including the business size standard applicable to the NAICS code referenced for this solicitation), at the time this offer is submitted and are incorporated in this offer by reference (see FAR 4.1201), except for paragraphs ______________.


[Offeror to identify the applicable paragraphs at (c) through (u) of this provision that the offeror has completed for the purposes of this solicitation only, if any.


These amended representation(s) and/or certification(s) are also incorporated in this offer and are current, accurate, and complete as of the date of this offer.


Any changes provided by the offeror are applicable to this solicitation only, and do not result in an update to the representations and certifications posted electronically on SAM.]


All vendors responding must be registered with the System for Award Management (SAM), which can be found at https://www.sam.gov by contract award.


52.212-4 CONTRACT TERMS AND CONDITIONS - COMMERCIAL ITEMS (OCT 2018)
The clause at 52.212-4, Contract Terms and Conditions-Commercial Items, is applicable to this acquisition. Incorporated by Reference



52.212-5 CONTRACT TERMS AND CONDITIONS REQUIRED TO IMPLEMENT STATUTES OR EXECUTIVE ORDERS - COMMERCIAL ITEMS (MAY 2019)


(a) The Contractor shall comply with the following Federal Acquisition Regulation (FAR) clauses, which are incorporated in this contract by reference, to implement provisions of law or Executive orders applicable to acquisitions of commercial items:
(1) 52.203-19, Prohibition on Requiring Certain Internal Confidentiality Agreements or Statements (Jan 2017) (section 743 of Division E, Title VII, of the Consolidated and Further Continuing Appropriations Act, 2015 (Pub. L. 113-235) and its successor provisions in subsequent appropriations acts (and as extended in continuing resolutions)).
(2) 52.204-23, Prohibition on Contracting for Hardware, Software, and Services Developed or Provided by Kaspersky Lab and Other Covered Entities (Jul 2018) (Section 1634 of Pub. L. 115-91).
(3) 52.209-10, Prohibition on Contracting with Inverted Domestic Corporations (Nov 2015).
(4) 52.233-3, Protest After Award (Aug 1996) (31 U.S.C. 3553).
(5) 52.233-4, Applicable Law for Breach of Contract Claim (Oct 2004) (Public Laws 108-77 and 108-78 (19 U.S.C. 3805 note)).
(b) The Contractor shall comply with the FAR clauses in this paragraph (b) that the Contracting Officer has indicated as being incorporated in this contract by reference to implement provisions of law or Executive orders applicable to acquisitions of commercial items:
[Contracting Officer check as appropriate.]
___(1) 52.203-6, Restrictions on Subcontractor Sales to the Government (Sept 2006), with Alternate I (Oct 1995) (41 U.S.C. 4704 and 10 U.S.C. 2402).
___(2) 52.203-13, Contractor Code of Business Ethics and Conduct (Oct 2015) (41 U.S.C. 3509)).
¬¬¬¬____(3) 52.203-15, Whistleblower Protections under the American Recovery and Reinvestment Act of 2009 (June 2010) (Section 1553 of Pub. L. 111-5). (Applies to contracts funded by the American Recovery and Reinvestment Act of 2009.)
__X_(4) 52.204-10, Reporting Executive Compensation and First-Tier Subcontract Awards (Oct 2018) (Pub. L. 109-282) (31 U.S.C. 6101 note).
____(5) [Reserved].
____(6) 52.204-14, Service Contract Reporting Requirements (Oct 2016) (Pub. L. 111-117, section 743 of Div. C).
____(7) 52.204-15, Service Contract Reporting Requirements for Indefinite-Delivery Contracts (Oct 2016) (Pub. L. 111-117, section 743 of Div. C).
_X__(8) 52.209-6, Protecting the Government's Interest When Subcontracting with Contractors Debarred, Suspended, or Proposed for Debarment. (Oct 2015) (31 U.S.C. 6101 note).
____(9) 52.209-9, Updates of Publicly Available Information Regarding Responsibility Matters (Oct 2018) (41 U.S.C. 2313).
____(10) [Reserved].
____(11) (i) 52.219-3, Notice of HUBZone Set-Aside or Sole-Source Award (Nov 2011) (15 U.S.C.657a).
____(ii) Alternate I (Nov 2011) of 52.219-3.
____(12) (i) 52.219-4, Notice of Price Evaluation Preference for HUBZone Small Business Concerns (Oct 2014) (if the offeror elects to waive the preference, it shall so indicate in its offer) (15 U.S.C. 657a).
____(ii) Alternate I (Jan 2011) of 52.219-4.
____(13) [Reserved]
____(14) (i) 52.219-6, Notice of Total Small Business Set-Aside (Nov 2011) (15 U.S.C.644).
____(ii) Alternate I (Nov 2011).
____(iii) Alternate II (Nov 2011).
____(15) (i) 52.219-7, Notice of Partial Small Business Set-Aside (June 2003) (15 U.S.C. 644).
____(ii) Alternate I (Oct 1995) of 52.219-7.
____(iii) Alternate II (Mar 2004) of 52.219-7.
____(16) 52.219-8, Utilization of Small Business Concerns (Oct 2018) (15 U.S.C. 637(d)(2) and (3)).
____(17) (i) 52.219-9, Small Business Subcontracting Plan (Aug 2018) (15 U.S.C. 637(d)(4))
_____(ii) Alternate I (Jan 2017) of 52.219-9.
_____(iii) Alternate II (Nov 2016) of 52.219-9.
____(iv) Alternate III (Nov 2016) of 52.219-9.
_____(v) Alternate IV (Aug 2018) of 52.219-9
_____(18) 52.219-13, Notice of Set-Aside of Orders (Nov 2011) (15 U.S.C. 644(r)).
_____(19) 52.219-14, Limitations on Subcontracting (Jan 2017) (15 U.S.C.637(a)(14)).
_____(20) 52.219-16, Liquidated Damages-Subcontracting Plan (Jan 1999) (15 U.S.C. 637(d)(4)(F)(i)).
_____(21) 52.219-27, Notice of Service-Disabled Veteran-Owned Small Business Set-Aside (Nov 2011) (15 U.S.C. 657f).
_____(22) 52.219-28, Post Award Small Business Program Rerepresentation (Jul 2013) (15 U.S.C. 632(a)(2)).
_____(23) 52.219-29, Notice of Set-Aside for, or Sole Source Award to, Economically Disadvantaged Women-Owned Small Business Concerns (Dec 2015) (15 U.S.C. 637(m)).
_____(24) 52.219-30, Notice of Set-Aside for, or Sole Source Award to, Women-Owned Small Business Concerns Eligible Under the Women-Owned Small Business Program (Dec 2015) (15 U.S.C. 637(m)).
_____(25) 52.222-3, Convict Labor (June 2003) (E.O.11755).
__X_(26) 52.222-19, Child Labor-Cooperation with Authorities and Remedies (Jan 2018) (E.O.13126).
_X__(27) 52.222-21, Prohibition of Segregated Facilities (Apr 2015).
_X__(28) (i) 52.222-26, Equal Opportunity (Sept 2016) (E.O.11246).
____(ii) Alternate I (Feb 1999) of 52.222-26.
____(29) (i) 52.222-35, Equal Opportunity for Veterans (Oct 2015) (38 U.S.C. 4212).
____(ii) Alternate I (July 2014) of 52.222-35.
____(30) (i) 52.222-36, Equal Opportunity for Workers with Disabilities (Jul 2014) ____(29 U.S.C.793).
____(ii) Alternate I (July 2014) of 52.222-36.
____(31) 52.222-37, Employment Reports on Veterans (Feb 2016) (38 U.S.C. 4212).
____(32) 52.222-40, Notification of Employee Rights Under the National Labor Relations Act (Dec 2010) (E.O. 13496).
_X___(33) (i) 52.222-50, Combating Trafficking in Persons (Jan 2019) (22 U.S.C. chapter 78 and E.O. 13627).
____(ii) Alternate I (Mar 2015) of 52.222-50 (22 U.S.C. chapter 78 and E.O. 13627).
____(34) 52.222-54, Employment Eligibility Verification (Oct 2015). (Executive Order 12989). (Not applicable to the acquisition of
____(34) 52.222-54, Employment Eligibility Verification (Oct 2015). (Executive Order 12989). (Not applicable to the acquisition of commercially available off-the-shelf items or certain other types of commercial items as prescribed in 22.1803.)
____(35) (i) 52.223-9, Estimate of Percentage of Recovered Material Content for EPA-Designated Items (May 2008) (42 U.S.C. 6962(c)(3)(A)(ii)). (Not applicable to the acquisition of commercially available off-the-shelf items.)
____(ii) Alternate I (May 2008) of 52.223-9 (42 U.S.C. 6962(i)(2)©). (Not applicable to the acquisition of commercially available off-the-shelf items.)
____(36) 52.223-11, Ozone-Depleting Substances and High Global Warming Potential Hydrofluorocarbons (Jun 2016) (E.O. 13693).
____(37) 52.223-12, Maintenance, Service, Repair, or Disposal of Refrigeration Equipment and Air Conditioners (Jun2016) (E.O. 13693).
____(38) (i) 52.223-13, Acquisition of EPEAT®-Registered Imaging Equipment (Jun 2014) (E.O.s 13423 and 13514).
____(ii) Alternate I (Oct 2015) of 52.223-13.
____(39) (i) 52.223-14, Acquisition of EPEAT®-Registered Televisions (Jun 2014) (E.O.s 13423 and 13514).
____(ii) Alternate I (Jun 2014) of 52.223-14.
____(40) 52.223-15, Energy Efficiency in Energy-Consuming Products (Dec 2007) (42 U.S.C. 8259b).
____(41) (i) 52.223-16, Acquisition of EPEAT®-Registered Personal Computer Products (Oct 2015) (E.O.s 13423 and 13514).
____(ii) Alternate I (Jun 2014) of 52.223-16.
__x_(42) 52.223-18, Encouraging Contractor Policies to Ban Text Messaging While Driving (Aug 2011) (E.O. 13513).
¬¬____(43) 52.223-20, Aerosols (Jun 2016) (E.O. 13693).
____(44) 52.223-21, Foams (Jun 2016) (E.O. 13693).
____(45) (i) 52.224-3 Privacy Training (Jan 2017) (5 U.S.C. 552 a).
____(i) 52.224-3 Privacy Training (Jan 2017) (5 U.S.C. 552 a).
____(ii) Alternate I (Jan 2017) of 52.224-3.
____(46) 52.225-1, Buy American-Supplies (May 2014) (41 U.S.C. chapter 83).
____(47) (i) 52.225-3, Buy American-Free Trade Agreements-Israeli Trade Act (May 2014) (41 U.S.C. chapter 83, 19 U.S.C. 3301 note, 19 U.S.C. 2112 note, 19 U.S.C. 3805 note, 19 U.S.C. 4001 note, Pub. L. 103-182, 108-77, 108-78, 108-286, 108-302, 109-53, 109-169, 109-283, 110-138, 112-41, 112-42, and 112-43.
____(ii) Alternate I (May 2014) of 52.225-3.
____(iii) Alternate II (May 2014) of 52.225-3.
____(iv) Alternate III (May 2014) of 52.225-3.
____(48) 52.225-5, Trade Agreements (Aug 2018) (19 U.S.C. 2501, et seq., 19 U.S.C. 3301 note).
_x___(49) 52.225-13, Restrictions on Certain Foreign Purchases (June 2008) (E.O.'s, proclamations, and statutes administered by the Office of Foreign Assets Control of the Department of the Treasury).
___(50) 52.225-26, Contractors Performing Private Security Functions Outside the United States (Oct 2016) (Section 862, as amended, of the National Defense Authorization Act for Fiscal Year 2008; 10 U.S.C. 2302 Note).
___(51) 52.226-4, Notice of Disaster or Emergency Area Set-Aside (Nov 2007) (42 U.S.C. 5150).
___(52) 52.226-5, Restrictions on Subcontracting Outside Disaster or Emergency Area (Nov 2007) (42 U.S.C. 5150).
___(53) 52.232-29, Terms for Financing of Purchases of Commercial Items (Feb 2002) (41 U.S.C.4505, 10 U.S.C.2307(f)).
___(54) 52.232-30, Installment Payments for Commercial Items (Jan 2017) (41 U.S.C.4505, 10 U.S.C.2307(f)).
_x__(55) 52.232-33, Payment by Electronic Funds Transfer-System for Award Management (Oct 2018) (31 U.S.C. 3332).
___(56) 52.232-34, Payment by Electronic Funds Transfer-Other than System for Award Management (Jul 2013) (31 U.S.C.3332).
___(57) 52.232-36, Payment by Third Party (May 2014) (31 U.S.C.3332).
___(58) 52.239-1, Privacy or Security Safeguards (Aug 1996) (5 U.S.C. 552a).
___(59) 52.242-5, Payments to Small Business Subcontractors (Jan 2017) (15 U.S.C. 637(d)(13)).
___(60) (i) 52.247-64, Preference for Privately Owned U.S.-Flag Commercial Vessels (Feb 2006) (46 U.S.C. Appx. 1241(b) and 10 U.S.C. 2631).
___(ii) Alternate I (Apr 2003) of 52.247-64.
___(iii) Alternate II (Feb 2006) of 52.247-64.


(c) The Contractor shall comply with the FAR clauses in this paragraph (c), applicable to commercial services, that the Contracting Officer has indicated as being incorporated in this contract by reference to implement provisions of law or Executive orders applicable to acquisitions of commercial items:
[Contracting Officer check as appropriate.]


___(1) 52.222-17, Nondisplacement of Qualified Workers (May 2014)(E.O. 13495).
____(2) 52.222-41, Service Contract Labor Standards (Aug 2018) (41 U.S.C. chapter 67).
____(3) 52.222-42, Statement of Equivalent Rates for Federal Hires (May 2014) (29 U.S.C. 206 and 41 U.S.C. chapter 67).
____(4) 52.222-43, Fair Labor Standards Act and Service Contract Labor Standards-Price Adjustment (Multiple Year and Option Contracts) (Aug 2014) (29 U.S.C. 206 and 41 U.S.C. chapter 67).
____(5) 52.222-44, Fair Labor Standards Act and Service Contract Labor Standards-Price Adjustment (May 2014) (29 U.S.C. 206 and 41 U.S.C. chapter 67).
____(6) 52.222-51, Exemption from Application of the Service Contract Labor Standards to Contracts for Maintenance, Calibration, or Repair of Certain Equipment-Requirements (May 2014) (41 U.S.C. chapter 67).
____(7) 52.222-53, Exemption from Application of the Service Contract Labor Standards to Contracts for Certain Services-Requirements (May 2014) (41 U.S.C. chapter 67).
____(8) 52.222-55, Minimum Wages Under Executive Order 13658 (Dec 2015).
____(9) 52.222-62, Paid Sick Leave Under Executive Order 13706 (Jan 2017) (E.O. 13706).
___(10) 52.226-6, Promoting Excess Food Donation to Nonprofit Organizations (May 2014) (42 U.S.C. 1792).


(d) Comptroller General Examination of Record. The Contractor shall comply with the provisions of this paragraph (d) if this contract was awarded using other than sealed bid, is in excess of the simplified acquisition threshold, and does not contain the clause at 52.215-2, Audit and Records-Negotiation.


(1) The Comptroller General of the United States, or an authorized representative of the Comptroller General, shall have access to and right to examine any of the Contractor's directly pertinent records involving transactions related to this contract.


(2) The Contractor shall make available at its offices at all reasonable times the records, materials, and other evidence for examination, audit, or reproduction, until 3 years after final payment under this contract or for any shorter period specified in FAR subpart 4.7, Contractor Records Retention, of the other clauses of this contract. If this contract is completely or partially terminated, the records relating to the work terminated shall be made available for 3 years after any resulting final termination settlement. Records relating to appeals under the disputes clause or to litigation or the settlement of claims arising under or relating to this contract shall be made available until such appeals, litigation, or claims are finally resolved.


(3) As used in this clause, records include books, documents, accounting procedures and practices, and other data, regardless of type and regardless of form. This does not require the Contractor to create or maintain any record that the Contractor does not maintain in the ordinary course of business or pursuant to a provision of law.


(e) (1) Notwithstanding the requirements of the clauses in paragraphs (a), (b), (c), and (d) of this clause, the Contractor is not required to flow down any FAR clause, other than those in this paragraph (e)(1) in a subcontract for commercial items. Unless otherwise indicated below, the extent of the flow down shall be as required by the clause-
(i) 52.203-13, Contractor Code of Business Ethics and Conduct (Oct 2015) (41 U.S.C. 3509).
(ii) 52.203-19, Prohibition on Requiring Certain Internal Confidentiality Agreements or Statements (Jan 2017) (section 743 of Division E, Title VII, of the Consolidated and Further Continuing Appropriations Act, 2015 (Pub. L. 113-235) and its successor provisions in subsequent appropriations acts (and as extended in continuing resolutions)).
(iii) 52.204-23, Prohibition on Contracting for Hardware, Software, and Services Developed or Provided by Kaspersky Lab and Other Covered Entities (Jul 2018) (Section 1634 of Pub. L. 115-91).
(iv) 52.219-8, Utilization of Small Business Concerns (Oct 2018) (15 U.S.C.637(d)(2) and (3)), in all subcontracts that offer further subcontracting opportunities. If the subcontract (except subcontracts to small business concerns) exceeds $700,000 ($1.5 million for construction of any public facility), the subcontractor must include 52.219-8 in lower tier subcontracts that offer subcontracting opportunities.
(v) 52.222-17, Nondisplacement of Qualified Workers (May 2014) (E.O. 13495). Flow down required in accordance with paragraph (l) of FAR clause 52.222-17.
(vi) 52.222-21, Prohibition of Segregated Facilities (Apr 2015).
(vii) 52.222-26, Equal Opportunity (Sept 2015) (E.O.11246).
(viii) 52.222-35, Equal Opportunity for Veterans (Oct 2015) (38 U.S.C.4212).
(ix) 52.222-36, Equal Opportunity for Workers with Disabilities (Jul 2014) (29 U.S.C.793).
(x) 52.222-37, Employment Reports on Veterans (Feb 2016) (38 U.S.C.4212)
(xi) 52.222-40, Notification of Employee Rights Under the National Labor Relations Act (Dec 2010) (E.O. 13496). Flow down required in accordance with paragraph (f) of FAR clause 52.222-40.
(xii) 52.222-41, Service Contract Labor Standards (Aug 2018) (41 U.S.C. chapter 67).
(xiii) (A) 52.222-50, Combating Trafficking in Persons (Jan 2019) (22 U.S.C. chapter 78 and E.O 13627).
(B) Alternate I (Mar 2015) of 52.222-50(22 U.S.C. chapter 78 and E.O 13627).
(xiv) 52.222-51, Exemption from Application of the Service Contract Labor Standards to Contracts for Maintenance, Calibration, or Repair of Certain Equipment-Requirements (May 2014) (41 U.S.C. chapter 67).
(xv) 52.222-53, Exemption from Application of the Service Contract Labor Standards to Contracts for Certain Services-Requirements (May 2014) (41 U.S.C. chapter 67).
(xvi) 52.222-54, Employment Eligibility Verification (Oct 2015) (E.O. 12989).
(xvii) 52.222-55, Minimum Wages Under Executive Order 13658 (Dec 2015).
(xviii) 52.222-62, Paid Sick Leave Under Executive Order 13706 (Jan 2017) (E.O. 13706).
(xix) (A) 52.224-3, Privacy Training (Jan 2017) (5 U.S.C. 552a).
(B) Alternate I (Jan 2017) of 52.224-3.
(xx) 52.225-26, Contractors Performing Private Security Functions Outside the United States (Oct 2016) (Section 862, as amended, of the National Defense Authorization Act for Fiscal Year 2008; 10 U.S.C. 2302 Note).
(xxi) 52.226-6, Promoting Excess Food Donation to Nonprofit Organizations (May 2014) (42 U.S.C. 1792). Flow down required in accordance with paragraph (e) of FAR clause 52.226-6.
(xxii) 52.247-64, Preference for Privately Owned U.S.-Flag Commercial Vessels (Feb 2006) (46 U.S.C. Appx.1241(b) and 10 U.S.C.2631). Flow down required in accordance with paragraph (d) of FAR clause 52.247-64.
(2) While not required, the Contractor may include in its subcontracts for commercial items a minimal number of additional clauses necessary to satisfy its contractual obligations.
(End of clause)



52.217-8 OPTION TO EXTEND SERVICES (NOV 1999)


The Government may require continued performance of any services within the limits and at the rates specified in the contract. These rates may be adjusted only as a result of revisions to prevailing labor rates provided by the Secretary of Labor. The option provision may be exercised more than once, but the total extension of performance hereunder shall not exceed 6 months. The Contracting Officer may exercise the option by written notice to the Contractor within 1 day of contract end date.


(End of Clause)



FAR 52.217-9 OPTION TO EXTEND THE TERM OF THE CONTRACT (MAR 2000)


(a) The Government may extend the term of this contract by written notice to the Contractor within 1 day of contract end date; provided that the Government gives the Contractor a preliminary written notice of its intent to extend at least 30 days before the contract expires. The preliminary notice does not commit the Government to an extension.
(b) If the Government exercises this option, the extended contract shall be considered to include this option clause.
(c) The total duration of this contract, including the exercise of any options under this clause, shall not exceed 5 years


(End of Clause)



DEPARTMENT OF TREASURY ACQUISITION REGULATION CLAUSES
1052.210-70 (DTAR) CONTRACTOR PUBLICITY (APR 2015)
The Contractor, or any entity or representative acting on behalf of the Contractor, shall not refer to the supplies or services furnished pursuant to the provisions of this contract in any news release or commercial advertising, or in connection with any news release or commercial advertising, without first obtaining explicit written consent to do so from the Contracting Officer. Should any reference to such supplies or services appear in any news release or commercial advertising issued by or on behalf of the Contractor without the required consent, the Government shall consider institution of all remedies available under applicable law, including 31 U.S.C. 333, and this contract. Further, any violation of this clause may be considered as part of the evaluation of past performance.
(End of clause)
1052.232-7003 (DTAR) ELECTRONIC SUBMISSION OF PAYMENT REQUESTS (APR 2015)
(a) Definitions. As used in this clause-
(1) "Payment request" means a bill, voucher, invoice, or request for contract financing payment with associated supporting documentation. The payment request must comply with the requirements identified in FAR 32.905(b), "Content of Invoices" and the applicable Payment clause included in this contract.
(b) Except as provided in paragraph (c) of this clause, the Contractor shall submit payment requests electronically using the Invoice Processing Platform (IPP). Information regarding IPP, including IPP Customer Support contact information, is available at www.ipp.gov or any successor site.
(c) The Contractor may submit payment requests using other than IPP only when the Contracting Officer authorizes alternate procedures in writing in accordance with Treasury procedures.
(d) If alternate payment procedures are authorized, the Contractor shall include a copy of the Contracting Officer's written authorization with each payment request.
(End of clause)


OFFICE OF THE COMPTROLLER OF CURRENCY CLAUSES


OCC 1052.239-8000 ELECTRONIC AND INFORMATION TECHNOLOGY ACCESSIBILITY (JUN 2014)


(a) Pursuant to Section 508 of the Rehabilitation Act of 1973 (29 U.S.C. 794d), as amended by the Workforce Investment Act of 1998, all electronic and information technology (EIT) products and services developed, acquired, maintained, or used under this contract/order must comply with the "Electronic and Information Technology Accessibility Provisions" set forth by the Architectural and Transportation Barriers Compliance Board (also referred to as the "Access Board") in 36 CFR Part 1194. Information about Section 508 is available at http://www.section508.gov/. The complete text of Section 508 Final Provisions can be accessed at http://www.access-board.gov/sec508/standards.htm.


(b) The Section 508 accessibility standards applicable to this contract/order are identified in the Statement of Work/Specification/Performance Work Statement. If it is determined by the Government that EIT products and services provided by the Contractor do not conform to the described accessibility standards in the Product Assessment Template, remediation of the products or services to the level of conformance specified in the Contractor's Product Assessment Template will be the responsibility of the Contractor at its own expense.


(c) In the event of a modification(s) to this contract/order, which adds new EIT products or services or revises the type of, or specifications for, products or services the Contractor is to provide, including EIT deliverables such as electronic documents and reports, the Contracting Officer may require that the Contractor submit a completed Voluntary Product Accessibility Template found at http://www.itic.org/public-policy/accessibility, to assist the Government in determining that the EIT products or services support Section 508 accessibility standards.


(End of Clause)



1052.242-8001 (OCC) POINT OF CONTACT (JUNE 2014)


(a) The Point of Contact (POC) for this award is responsible for inspection and invoice approval, and where required, acceptance of deliverables or services rendered.


(b) The POC does not have authority to take any action, either directly or indirectly, that would change pricing, quantity, place of performance, delivery schedule, or any terms and conditions of this award or to direct the contractor in the accomplishment of effort which goes beyond the scope.


(c) If the contractor believes the POC has changed the scope of this contract, order or blanket purchase agreement, the contractor shall promptly notify the Contracting Officer (CO) verbally or in writing. In the event the contractor effects any change at the direction of any person other than the CO, the change will be considered to have been made without authority and no adjustment will be made in the award price to cover any increase incurred as a result thereof.


(d) The POC for this award is:


Name: [Insert Name]
Address: Office of the Comptroller of the Currency
400 7th Street SW, Mailstop XX
Washington, D.C. 20219


Telephone: [202-XXX-XXXX]
E-mail: poc.employee@occ.treas.gov


(End of Clause)



OCC 1052.243-8001 AUTHORIZED CHANGES ONLY BY THE CONTRACTING OFFICER (SEP 2016)


(a) Except as specified in paragraph (b) below, no order, statement, or conduct of Government personnel who provide technical direction or in any other manner communicates with contractor personnel during the performance of this contract shall constitute a change under the "Changes" clause of this contract.
(b) The Contractor shall not comply with any order, direction or request of Government personnel unless it is issued in writing and signed by the Contracting Officer (CO), or is pursuant to specific authority otherwise included as a part of this contract.
(c) The CO is the only person authorized to approve changes in any of the requirements of this contract and notwithstanding provisions contained elsewhere in this contract, the said authority remains solely the CO's. In the event the Contractor effects any change at the direction of any person other than the CO, the change will be considered to have been made without authority and no adjustment will be made in the contract price to cover any increase in charges incurred as a result thereof. The primary CO will be identified via separate letter to the contractor. Any CO with appropriate warrant authority may direct changes through a modification to the contract.


(End of Clause)



1052.245-8003 CONFIDENTIAL OR SENSITIVE INFORMATION (JAN 2014)


(a) Because of the proprietary nature of such information, the contractor understands that work performed by and information released to the contractor is sensitive in nature and shall not be disclosed to anyone other than the Office of the Comptroller of the Currency (OCC) (Government) employees assigned to the contract and other contractor personnel the Government authorizes to receive the information. The contractor agrees to protect all confidential and/or proprietary information received by or provided to the contractor pursuant to this contract from unauthorized disclosure or use for as long as the information remains proprietary or confidential and further agrees that it will not use such information for any purpose other than that relating to the performance of this contract. For purposes of the contract, all information provided to or received by the contractor is deemed confidential and proprietary.
(b) The contractor shall execute and is responsible for having all of its employees, subcontractor employees, and agents working under the contract and/or having access to sensitive information under this contract execute a "Conditional Access to Sensitive but Unclassified Information Non-Disclosure Agreement.", hereafter referred to as an NDA, provided as Attachment 2 to this contract. This NDA provides that sensitive but unclassified information provided to the contractor or its employees, subcontractors, or agents, shall not, except as permitted in connection with the performance of the contract, be further disclosed or used without the prior written approval of the Government.
(c) Contractor employees processed in the Personnel and Administration Security System (PASS), will complete the NDA electronically.
(d) Contractor employees processed outside of PASS, will complete the attached hard copy NDA and submit to the Contracting Officer (CO).
(e) Executed copies of the NDA are required by each contractor employee, subcontractor employee or agent who will perform work on the contract before they can begin actual performance under the contract.


(End of Clause)



1052.245-8008 (OCC) INFORMATION SECURITY REQUIREMENTS FOR UNCLASSIFIED OCC INFORMATION TECHNOLOGY RESOURCES (JAN 2014)
I. DEFINITIONS Definitions, as used in this clause, generally refer to the Code of Federal Regulations (CFR) unless a more specific provision is noted below.
Adequate Security
Security that is commensurate with the risk and magnitude of harm resulting from the loss, misuse, or unauthorized access to or modification of information. This includes assuring that systems and applications in use operate effectively and provide appropriate confidentiality, integrity, and availability through the use of managerial, operational, and technical security controls.
Availability
To ensure the timely and reliable access to, and use of, information.
Confidentiality
Preserving authorized restrictions on access and disclosure, including means for protecting personal privacy and proprietary information.
Information Assurance
Information Assurance (IA) are the measures that protect and defend information and information systems by ensuring their availability, integrity, authentication, confidentiality, and non-repudiation. This includes providing for restoration of information systems by incorporating protection, detection, and reaction capabilities.
Information Resource
An information resource encompasses both information and information related resources such as personnel, equipment, data, and information technology.
Information System
A discrete set of information resources organized for the collection, processing, maintenance, transmission, and dissemination of information, in accordance with defined procedures, whether automated or manual.
Information Technology
With respect to the Office of the Comptroller of the Currency (OCC), information technology means any equipment or interconnected system or subsystem of equipment, used in the automatic acquisition, storage, analysis, evaluation, manipulation, management, movement, control, display, switching, interchange, transmission, or reception of data or information by the OCC, if the equipment is used by the OCC directly or is used by a contractor under a contract with the OCC that requires the use:
(i) of that equipment; or
(ii) of that equipment to a significant extent in the performance of a service or the furnishing of a product.
Information technology includes computers, ancillary equipment (including imaging peripherals, input, output, and storage devices necessary for security and surveillance), peripheral equipment designed to be controlled by the central processing unit of a computer, software, firmware and similar procedures, services (including support services), and related resources; but does not include any equipment acquired by a federal contractor incidental to a federal contract.
Integrity
Guarding against improper information modification or destruction, and includes ensuring information non-repudiation and authenticity.
Service Provider
Service Providers are non-OCC entities that support the OCC mission and information systems. These are any individual or other legal entity that (1) directly or indirectly (e.g., through an affiliate), submits offers for or is awarded, or reasonably may be expected to submit offers for or be awarded, a Government contract, including a contract for carriage under Government or commercial bills of lading, or a subcontract under a Government contract; or (2) conducts business, or reasonably may be expected to conduct business, with the Government as an agent or representative of another service provider.
Service providers are classified one of two ways: contracted or shared.
• Contracted Service Provider
A Contracted Service Provider (CSP) is a general term used to refer to outsourced business processes supported by private sector information systems, outsourced information technologies, or outsourced information services. A CSP performs clearly defined functions for which there are readily identifiable security considerations and needs that are addressed in both acquisition and operations.
• Shared Service Provider
A Shared Service Provider (SSP) is another federal agency functioning as a service provider for the OCC. The OCC and other federal agency would sign a Memorandum of Understanding (MOU), Interagency Agreement (IAA) or Data Exchange Agreement.
II. GENERAL REQUIREMENTS


(1) The service provider shall be responsible for adhering to OCC information technology (IT) security requirements for all information systems connected to an OCC network or operated by the service provider for, or on behalf of, the OCC, regardless of location. This clause applies to all or any part of the contract that includes information technology, information resources or services for which the service provider must have physical or electronic access to OCC information.
(2) OCC information technology and information assigned to service providers shall remain in the United States. The maintenance, operation, and/or processing of said technology and information shall take place, and originate from, within the United States.
(3) The service provider shall maintain a complete and accurate inventory of all OCC-provided information resources. The inventory shall be made available for inspection immediately upon request by the OCC.
(4) The service provider facility hosting OCC information resources shall meet all applicable federal, state, and local zoning, environmental, and building laws and regulations. The facility shall include protection against unauthorized access at all hours, including alarms and notification systems should such protection be breached.
(5) Confirmed security compromises to OCC information shall be reported to the Contracting Officer (CO), the Contracting Officer's Representative (COR), and the Officer of Security (OS) within 60 minutes of discovery by the service provider.
(6) The service provider shall ensure that its employees, in the performance of the contract, receive and document annual information security awareness training (see Clause No. 1052.245-8001) in accordance with Office of Management and Budget (OMB) Circular A-130 and Federal Information Security Management Act of 2002 (FISMA) requirements.
(7) The service provider shall grant the Government access to any and all facilities and information resources used in support of the contract. The OCC will conduct annual reviews to ensure that the security requirements in the contract are implemented, enforced, effective, and operating as intended. These reviews include, but are not limited to, comprehensive technical testing of the control environment used to safeguard OCC information resources.
(8) At the expiration of the contract, the service provider shall return all OCC information resources provided to, or generated by, the service provider during the period of the contract. The service provider shall provide certification that all OCC information has been sanitized from any non-GFE information system in accordance with OCC standards and procedures. All equipment sanitization procedures must be environmentally sound as outlined by the U.S. Environmental Protection Agency (EPA).
(9) The service provider shall comply with the terms of the Government furnished property clauses in this contract for any OCC-issued IT that is lost, stolen, missing, unaccounted for, or damaged.
(10) For the purposes of application development, the OCC encourages and prefers the use of web-based, commercial-off-the-shelf solutions. Web-based applications must be configured to work with multiple browser and operating system types and may not favor one browser type over another.
(11) The service provider shall adhere to OCC common security configurations and practices. Security configurations and practices include:
A. The provider of information technology shall certify applications are fully functional and operate as intended on systems using the Federal Desktop Core Configuration (FDCC) and other operating system and application standards.
B. Final acceptance of the product will be based on the OCC interpretation of the National Institute of Standards and Technology, National Checklist Program Repository (NIST, NCPR). Checklists are available at the NIST, NCPR website. In situations where security configurations are not available for proposed technologies, the OCC will provide instruction.
C. The installation, operation, maintenance, and update of software shall not alter any OCC-accepted or established security configuration.
D. Applications designed for users shall run in standard user context without elevated system administrator privileges.
E. Products specifically designed for the purpose of Information Assurance (IA), and designated as such by the OCC, are exempt from these common security configuration requirements. Non-GFE IT is exempted by the OCC on a case-by-case basis.
(12) The service provider shall notify the CO and the COR of any organizational change or impact that may interfere with the full execution of the contract immediately upon identification.
(13) Throughout the term of the contract, should the service provider deliver a product or provide a service that does not meet (and maintain) these requirements, the service provider, at their own expense, shall correct issues within 90 days of notification by the CO.



III. ADDITIONAL REQUIREMENTS


(1) The service provider shall have fully completed, attested to, and submitted to the CO the OCC's Service Provider Self Assessment (OCC Form CC 9070-02) provided as Attachment [ Fill-in ] of the contract, prior to the execution of the contract.
(2) All service providers who conduct formal reviews of their internal controls over the services, systems, and facilities supporting the OCC shall provide the resultant reports to the CO immediately upon contract award and on an annual basis thereafter to be used as part of the OCC's Service Provider Review and Office of Management and Budget Circular A-123 compliance processes. Examples of such reports would include but are not limited to SAS-70 or SSAE-16 Type II audit reports performed by independent third parties. If not available, internal reviews of a similar nature will be acceptable. OCC will adhere to the requirements of a mutually acceptable Non-Disclosure Agreement with regard to the contents of these reports.
(3) The service provider shall maintain a computing environment with adequate security at all times. This includes, but is not limited to, the description and documentation of the processes and procedures that will be followed to ensure the security of IT resources that are developed, processed, transmitted, used, or maintained under this contract and comprehensive technical testing of the contractor's computing environment by the OCC.


(4) Prior to the execution of the contract, the OCC may validate adequate security controls in the contractor's environment. When a validation is required, the validation will be conducted by the OCC as part of an on-site inspection process.


(A) The service provider agrees to demonstrate, to personnel authorized by the OCC, the technical, operational, and management safeguards that protect the confidentiality, integrity, and availability of OCC information that it develops, processes, transmits, uses, or maintains during the execution of this contract.
(B) The on-site inspection serves to ensure the computing environment complies with Federal laws that include, but are not limited to, the Federal Information Security Management Act of 2002 (FISMA); and with Federal policies and procedures that include, but are not limited to, OMB Circular A-130, FIPS Publications 199 and 200, Department of the Treasury Directive 85-01, and OCC Policy and Procedures Manual 4000-1 (REV). Copies of these documents are maintained by the OCC Information Risk Management and are available upon request.
(C) The service provider shall maintain an active information security program. The program shall specifically address methods regarding handling and protecting OCC information at the contractor's site (including any information stored, processed, or transmitted using the contractor's computer systems), and the secure management, operation, maintenance, programming, and system administration of computer systems, networks, and telecommunications systems.
(D) The service provider may use additional safeguards to prevent use or disclosure of OCC information other than as provided for by this contract as deemed necessary.
(E) The service provider shall, at their own expense, take action to mitigate any harmful effect that is known to the service provider of a use or disclosure of OCC information by the contractor in violation of the requirements of this clause.


IV. OBLIGATIONS OF THE OCC
(1) OCC Security and Compliance Services (SCS) maintains information on current information security requirements and standards and will provide details upon request. The service provider will be notified of any substantive changes to information security requirements that have a significant impact on the Service Provider's information security obligations under this contract.
(2) The OCC will evaluate the need for a new on-site inspection at a minimum once each year. The OCC in its sole discretion may determine that a new on-site inspection is necessary.
(End of Clause)


OFFICE OF THE COMPTROLLER OF CURRENCY PROVISIONAL CLAUSES


OCC 1052.239-8001 ELECTRONIC AND INFORMATION TECHNOLOGY ACCESSIBILITY (JUNE 2014)


(a) Section 508 of the Rehabilitation Act of 1973 (29 U.S.C. 794d), as amended by the Workforce Investment Act of 1998, and the Architectural and Transportation Barriers Compliance Board Electronic and Information (EIT) Accessibility Standards (36 CFR Part 1194), require that, unless an exception applies, all EIT products and services developed, acquired, maintained, or used by any federal department or agency permit-
1. Federal employees with disabilities to have access to and use information and data that is comparable to the access and use of information and data by federal employees who are not individuals with disabilities; and
2. Members of the public with disabilities seeking information or services from a federal agency to have access to and use of information and data that is comparable to the access and use of information and data by members of the public who are not individuals with disabilities.


(b) Accordingly, any Contractor submitting a proposal/quotation/bid in response to this solicitation must demonstrate compliance with the established EIT accessibility standards. Information about Section 508 is available at http://www.section508.gov/. The complete text of Section 508 Final Provisions can be accessed at http://www.access-board.gov/sec508/standards.htm.


(c) The Section 508 accessibility standards applicable to this solicitation are identified in the Statement of Work/Specification/Performance Work Statement. In order to facilitate the Government's evaluation to determine whether EIT products and services proposed meet applicable Section 508 accessibility standards, offerors must prepare the Voluntary Product Accessibility Template (VPAT) found at http://www.itic.org/public-policy/accessibility, in accordance with its completion instructions. Additionally, offerors must complete the OCC IT Accessibility Questionnaire found at Attachment 1 of the solicitation. The purpose of the VPAT template and the OCC IT Accessibility Questionnaire is to assist OCC acquisition and program officials in determining that EIT products and services proposed support applicable Section 508 accessibility standards.


(d) Attestation: To the best of my knowledge, statements made in response to the VPAT and OCC IT Accessibility Questionnaire are complete, accurate, and were made by knowledgeable and qualified professionals in the internal control structure of my organization. The undersigned has authority to legally bind my organization and has been authorized to do so.


Corporate Officer Signature: ____________________________________


Printed Name/Title: ___________________________________________


Date: ________________


(e) If a Contractor claims its products or services, including EIT deliverables such as electronic documents and reports, meet applicable Section 508 accessibility standards in its completed VPAT and OCC IT Accessibility Questionnaire, and it is later determined by the Government - i.e., after award of a contract/order, that products or services delivered do not conform to the described accessibility standards in the Product Assessment Template and Questionnaire, remediation of the products or services to the level of conformance specified in the Contractor's Product Assessment Template and Questionnaire will be the responsibility of the Contractor and at its expense.


(End of provision)


Questions regarding this solicitation are due by May 22, 2019 at 12:00 Noon ET. Quotations are due June 3, 2019 at 2:00 PM ET via email transmission to Karen.green@occ.treas.gov.


Contact Karen A. Green at 202 649-8120 or Karen.green@occ.treas.gov for information regarding this solicitation.


ATTACHMENTS:
1-Voluntary Product Accessibility Template (VPAT)
2-Non-Disclosure Agreement



.

Attachments

Files attached to this notice, newest first
File Type Posted
VENDOR_QUESTIONS_AND_REPSONSES.pdf PDF
AccessibilityConformanceReport.doc DOC document
Non-Disclosure_Agreement_(Contractor_Employees).doc DOC document

On GovTribe

Work this opportunity on GovTribe

  • Track it in your pipeline
  • Find teaming partners
  • Similar opportunities
  • Ask GovTribe AI about this opportunity