250047-SHI INTERNATIONAL CONTRACT 2024056-02.PDF

Maricopa County — Formal (2025-04-04)

View PDF Item 63 Meeting page

Extracted text (via pymupdf) 443735 characters
City of Mesa 
Contract # 2024056-02 
for 
Information Technology Solutions Products and Services 
with 
SHI International 
Effective: July 2, 2024

The following documents comprise the executed contract between the City 
of Mesa, and SHI International effective July 2, 2024: 
I.
City of Mesa/SHI Signed Contract
II.
Supplier’s Response to the RFP, incorporated by reference
a. OMNIA Partners

Edward Quedens
Business Services Director
7/3/24 12:57 MST

Proposer Name: SHI International Corp.

SHI Response to 
The City of Mesa/ OMNIA 
 
2024056 Information Technology Solutions 
Products and Services 
December 21, 2023

December 21, 2023
Ted Stallings 
City of Mesa
480-644-2815
Ted.Stallings@MesaAZ.Gov
Dear Ted Stallings,
The City of Mesa is crucial in strengthening our educational institutions, enhancing government 
infrastructure, and bolstering critical services for our community. As a trusted partner for the past five 
years, and recipient of the 2023 OMNIA Public Sector Supplier of the Year award, SHI stands as one of 
the most seasoned and accomplished technology advisors in the public sector today. With rich 
experience spanning over 30 years and an impressive revenue of $14 billion, SHI has an in-depth 
understanding of the intricate and evolving technological needs faced by large municipalities such as the 
City of Mesa. 
During the last five years of the existing contract, we have successfully assisted in the digital 
transformation of infrastructure for over 4,000 unique government entities, leading to increased efficiency 
and enhanced constituent experiences. In 2023, our industry-leading public sector vertical contributed to 
nearly $500 million in sales to our existing City of Mesa/OMNIA Partners contract.
Beyond monetary gains, our culture is deeply rooted in customer satisfaction and long-term shared 
successes. This is reflected in the fact that over 97 percent of our success originates from existing 
customers, including the City of Mesa. Our extensive vendor relationships and contracting vehicles 
enable us to provide bespoke solutions tailored to specific needs and constraints. 
Our continued growth has allowed us to expand our offerings and service capabilities, ensuring we deliver 
cutting-edge, high-value IT solutions to the public sector. Whether cloud migration, security hardening, 
infrastructure optimization, or application modernization, SHI’s team of experts, backed by proven 
experience and robust partnerships, are equipped to execute projects of any scale and complexity while 
maximizing the value of taxpayer dollars. At SHI, we remain committed to leveraging technology for the 
greater public good.
We have had tremendous success growing the value of our first awarded contract and will continue our 
commitment to expanding the use of this contract and supporting City of Mesa/OMNIA members with the 
latest technology, cost savings, technical expertise, and compliant procurement. We appreciate the 
opportunity to participate in your RFP, 2024056 Information Technology Solutions Products and Services. 
We believe our proposal illustrates why we are best qualified to meet the needs of the City/OMNIA, 
providing evidence of our ability to deliver the highest quality solutions at the best possible cost. Should 
you have any questions regarding our response, or if you require additional information, please contact 
me at Maya_Lynch@shi.com or 732-754-1554 or your SHI Account Executive, Victoria Lewkowitz at 
Victoria_Lewkowitz@shi.com or 650-483-9333. Thank you for your consideration, and I look forward to 
sharing with you all SHI has to offer.

Version June 28, 2023 
2024056 
 
 
 
 
Page 48 of 137 
Exhibit F 
Federal Funds Certifications 
FEDERAL CERTIFICATIONS
ADDENDUM FOR AGREEMENT FUNDED BY U.S. FEDERAL GRANT
TO WHOM IT MAY CONCERN: 
 
Participating Agencies may elect to use federal funds to purchase under the Master Agreement. This form should be 
completed and returned. 
DEFINITIONS 
Contract means a legal instrument by which a non–Federal entity purchases property or services needed to carry out the 
project or program under a Federal award. The term as used in this part does not include a legal instrument, even if the non–
Federal entity considers it a contract, when the substance of the transaction meets the definition of a Federal award or 
subaward 
Contractor means an entity that receives a contract as defined in Contract. 
 
Cooperative agreement means a legal instrument of financial assistance between a Federal awarding agency or pass-
through entity and a non–Federal entity that, consistent with 31 U.S.C. 6302–6305: 
(a) Is used to enter into a relationship the principal purpose of which is to transfer anything of value from the Federal 
awarding agency or pass-through entity to the non–Federal entity to carry out a public purpose authorized by a law 
of the United States (see 31 U.S.C. 6101(3)); and not to acquire property or services for the Federal government or 
pass-through entity's direct benefit or use; 
(b) Is distinguished from a grant in that it provides for substantial involvement between the Federal awarding agency 
or pass-through entity and the non–Federal entity in carrying out the activity contemplated by the Federal award. 
(c) The term does not include: 
(1) A cooperative research and development agreement as defined in 15 U.S.C. 3710a; or 
(2) An agreement that provides only: 
(i) Direct United States Government cash assistance to an individual; 
(ii) A subsidy; 
(iii) A loan; 
(iv) A loan guarantee; or 
(v) Insurance. 
 
Federal awarding agency means the Federal agency that provides a Federal award directly to a non–Federal entity 
 
Federal award has the meaning, depending on the context, in either paragraph (a) or (b) of this section:  
(a)(1) The Federal financial assistance that a non–Federal entity receives directly from a Federal awarding agency 
or indirectly from a pass-through entity, as described in § 200.101 Applicability; or 
(2) The cost-reimbursement contract under the Federal Acquisition Regulations that a non–Federal entity 
receives directly from a Federal awarding agency or indirectly from a pass-through entity, as described in 
§ 200.101 Applicability. 
(b) The instrument setting forth the terms and conditions. The instrument is the grant agreement, cooperative 
agreement, other agreement for assistance covered in paragraph (b) of § 200.40 Federal financial assistance, or the 
cost-reimbursement contract awarded under the Federal Acquisition Regulations. 
(c) Federal award does not include other contracts that a Federal agency uses to buy goods or services from a 
contractor or a contract to operate Federal government owned, contractor operated facilities (GOCOs). 
(d) See also definitions of Federal financial assistance, grant agreement, and cooperative agreement. 
 
Non–Federal entity means a state, local government, Indian tribe, institution of higher education (IHE), or nonprofit

Version June 28, 2023 
2024056 
 
 
 
 
Page 49 of 137 
organization that carries out a Federal award as a recipient or subrecipient. 
 
Nonprofit organization means any corporation, trust, association, cooperative, or other organization, not including IHEs, 
that: 
(a) Is operated primarily for scientific, educational, service, charitable, or similar purposes in the public interest; 
(b) Is not organized primarily for profit; and 
(c) Uses net proceeds to maintain, improve, or expand the operations of the organization. 
 
Obligations means, when used in connection with a non–Federal entity's utilization of funds under a Federal award, orders 
placed for property and services, contracts and subawards made, and similar transactions during a given period that require 
payment by the non–Federal entity during the same or a future period. 
 
Pass-through entity means a non–Federal entity that provides a subaward to a subrecipient to carry out part of a Federal 
program. 
 
Recipient means a non–Federal entity that receives a Federal award directly from a Federal awarding agency to carry out an 
activity under a Federal program. The term recipient does not include subrecipients. 
 
Simplified acquisition threshold means the dollar amount below which a non–Federal entity may purchase property or 
services using small purchase methods. Non–Federal entities adopt small purchase procedures in order to expedite the 
purchase of items costing less than the simplified acquisition threshold. The simplified acquisition threshold is set by the 
Federal Acquisition Regulation at 48 CFR Subpart 2.1 (Definitions) and in accordance with 41 U.S.C. 1908. As of the 
publication of this part, the simplified acquisition threshold is $250,000, but this threshold is periodically adjusted for inflation. 
(Also see definition of § 200.67 Micro-purchase.) 
 
Subaward means an award provided by a pass-through entity to a subrecipient for the subrecipient to carry out part of a 
Federal award received by the pass-through entity. It does not include payments to a contractor or payments to an individual 
that is a beneficiary of a Federal program. A subaward may be provided through any form of legal agreement, including an 
agreement that the pass-through entity considers a contract. 
 
Subrecipient means a non–Federal entity that receives a subaward from a pass-through entity to carry out part of a Federal 
program; but does not include an individual that is a beneficiary of such program. A subrecipient may also be a recipient of 
other Federal awards directly from a Federal awarding agency. 
 
Termination means the ending of a Federal award, in whole or in part at any time prior to the planned end of period of 
performance. 
 
The following provisions may be required and apply when Participating Agency expends federal funds for any purchase 
resulting from this procurement process. Per FAR 52.204-24 and FAR 52.204-25, solicitations and resultant contracts shall 
contain the following provisions. 
 
52.204-24 Representation Regarding Certain Telecommunications and Video Surveillance Services or Equipment (Oct 
2020) 
The Offeror shall not complete the representation at paragraph (d)(1) of this provision if the Offeror has represented that it 
"does not provide covered telecommunications equipment or services as a part of its offered products or services to the 
Government in the performance of any contract, subcontract, or other contractual instrument" in paragraph (c)(1) in the provision 
at 52.204-26, Covered Telecommunications Equipment or Services—Representation, or in paragraph (v)(2)(i) of the provision 
at 52.212-3, Offeror Representations and Certifications-Commercial Items. The Offeror shall not complete the representation in 
paragraph (d)(2) of this provision if the Offeror has represented that it "does not use covered telecommunications equipment or 
services, or any equipment, system, or service that uses covered telecommunications equipment or services" in paragraph (c)(2) 
of the provision at 52.204-26, or in paragraph (v)(2)(ii) of the provision at 52.212-3. 
      (a) Definitions. As used in this provision—

Version June 28, 2023 
2024056 
 
 
 
 
Page 50 of 137 
      Backhaul, covered telecommunications equipment or services, critical technology, interconnection arrangements, 
reasonable inquiry, roaming, and substantial or essential component have the meanings provided in the clause 52.204-25, 
Prohibition on Contracting for Certain Telecommunications and Video Surveillance Services or Equipment. 
(b) Prohibition. 
(1) Section 889(a)(1)(A) of the John S. McCain National Defense Authorization Act for Fiscal Year 2019 (Pub. L. 115-232) 
prohibits the head of an executive agency on or after August 13, 2019, from procuring or obtaining, or extending or renewing a 
contract to procure or obtain, any equipment, system, or service that uses covered telecommunications equipment or services as 
a substantial or essential component of any system, or as critical technology as part of any system. Nothing in the prohibition 
shall be construed to— 
             (i) Prohibit the head of an executive agency from procuring with an entity to provide a service that connects to the 
facilities of a third-party, such as backhaul, roaming, or interconnection arrangements; or 
                (ii) Cover telecommunications equipment that cannot route or redirect user data traffic or cannot permit visibility into 
any user data or packets that such equipment transmits or otherwise handles. 
           (2) Section 889(a)(1)(B) of the John S. McCain National Defense Authorization Act for Fiscal Year 2019 (Pub. L. 115-
232) prohibits the head of an executive agency on or after August 13, 2020, from entering into a contract or extending or 
renewing a contract with an entity that uses any equipment, system, or service that uses covered telecommunications equipment 
or services as a substantial or essential component of any system, or as critical technology as part of any system. This 
prohibition applies to the use of covered telecommunications equipment or services, regardless of whether that use is in 
performance of work under a Federal contract. Nothing in the prohibition shall be construed to— 
                (i) Prohibit the head of an executive agency from procuring with an entity to provide a service that connects to the 
facilities of a third-party, such as backhaul, roaming, or interconnection arrangements; or 
                (ii) Cover telecommunications equipment that cannot route or redirect user data traffic or cannot permit visibility into 
any user data or packets that such equipment transmits or otherwise handles. 
      (c) Procedures. The Offeror shall review the list of excluded parties in the System for Award Management (SAM) 
(https://www.sam.gov) for entities excluded from receiving federal awards for "covered telecommunications equipment or 
services". 
      (d) Representation. The Offeror represents that— 
           (1) It  will,  will not provide covered telecommunications equipment or services to the Government in the 
performance of any contract, subcontract or other contractual instrument resulting from this solicitation. The Offeror shall provide 
the additional disclosure information required at paragraph (e)(1) of this section if the Offeror responds "will" in paragraph (d)(1) 
of this section; and 
           (2) After conducting a reasonable inquiry, for purposes of this representation, the Offeror represents that— 
          It  does,  does not use covered telecommunications equipment or services, or use any equipment, system, or 
service that uses covered telecommunications equipment or services. The Offeror shall provide the additional disclosure 
information required at paragraph (e)(2) of this section if the Offeror responds "does" in paragraph (d)(2) of this section. 
      (e) Disclosures.  
(1) Disclosure for the representation in paragraph (d)(1) of this provision. If the Offeror has responded "will" in the 
representation in paragraph (d)(1) of this provision, the Offeror shall provide the following information as part of the offer. 
                (i) For covered equipment— 
                     (A) The entity that produced the covered telecommunications equipment (include entity name, unique entity 
identifier, CAGE code, and whether the entity was the original equipment manufacturer (OEM) or a distributor, if known); 
                     (B) A description of all covered telecommunications equipment offered (include brand; model number, such as 
OEM number, manufacturer part number, or wholesaler number; and item description, as applicable); and 
                     (C) Explanation of the proposed use of covered telecommunications equipment and any factors relevant to 
determining if such use would be permissible under the prohibition in paragraph (b)(1) of this provision. 
                (ii) For covered services— 
                     (A) If the service is related to item maintenance: A description of all covered telecommunications services 
offered (include on the item being maintained: Brand; model number, such as OEM number, manufacturer part number, or 
wholesaler number; and item description, as applicable); or 
                     (B) If not associated with maintenance, the Product Service Code (PSC) of the service being provided; and 
explanation of the proposed use of covered telecommunications services and any factors relevant to determining if such use 
would be permissible under the prohibition in paragraph (b)(1) of this provision.

Version June 28, 2023 
2024056 
 
 
 
 
Page 51 of 137 
           (2) Disclosure for the representation in paragraph (d)(2) of this provision. If the Offeror has responded "does" in the 
representation in paragraph (d)(2) of this provision, the Offeror shall provide the following information as part of the offer: 
(i) For covered equipment— 
                     (A) The entity that produced the covered telecommunications equipment (include entity name, unique entity 
identifier, CAGE code, and whether the entity was the OEM or a distributor, if known); 
                     (B) A description of all covered telecommunications equipment offered (include brand; model number, such as 
OEM number, manufacturer part number, or wholesaler number; and item description, as applicable); and 
                     (C) Explanation of the proposed use of covered telecommunications equipment and any factors relevant to 
determining if such use would be permissible under the prohibition in paragraph (b)(2) of this provision. 
                (ii) For covered services— 
(A) If the service is related to item maintenance: A description of all covered telecommunications services 
offered (include on the item being maintained: Brand; model number, such as OEM number, manufacturer part number, or 
wholesaler number; and item description, as applicable); or 
(B) If not associated with maintenance, the PSC of the service being provided; and explanation of the proposed 
use of covered telecommunications services and any factors relevant to determining if such use would be permissible under the 
prohibition in paragraph (b)(2) of this provision. 
52.204-25 Prohibition on Contracting for Certain Telecommunications and Video Surveillance Services or Equipment 
(Aug 2020). 
(a) Definitions. As used in this clause— 
Backhaul means intermediate links between the core network, or backbone network, and the small subnetworks at the 
edge of the network (e.g., connecting cell phones/towers to the core telephone network). Backhaul can be wireless (e.g., 
microwave) or wired (e.g., fiber optic, coaxial cable, Ethernet). 
Covered foreign country means The People’s Republic of China. 
Covered telecommunications equipment or services means– 
(1) Telecommunications equipment produced by Huawei Technologies Company or ZTE Corporation (or any 
subsidiary or affiliate of such entities); 
(2) For the purpose of public safety, security of Government facilities, physical security surveillance of critical 
infrastructure, and other national security purposes, video surveillance and telecommunications equipment produced by Hytera 
Communications Corporation, Hangzhou Hikvision Digital Technology Company, or Dahua Technology Company (or any 
subsidiary or affiliate of such entities); 
(3) Telecommunications or video surveillance services provided by such entities or using such equipment; or 
(4) Telecommunications or video surveillance equipment or services produced or provided by an entity that the 
Secretary of Defense, in consultation with the Director of National Intelligence or the Director of the Federal Bureau of 
Investigation, reasonably believes to be an entity owned or controlled by, or otherwise connected to, the government of a 
covered foreign country. 
Critical technology means– 
(1) Defense articles or defense services included on the United States Munitions List set forth in the International 
Traffic in Arms Regulations under subchapter M of chapter I of title 22, Code of Federal Regulations; 
(2) Items included on the Commerce Control List set forth in Supplement No. 1 to part 774 of the Export Administration 
Regulations under subchapter C of chapter VII of title 15, Code of Federal Regulations, and controlled- 
(i) Pursuant to multilateral regimes, including for reasons relating to national security, chemical and biological 
weapons proliferation, nuclear nonproliferation, or missile technology; or 
(ii) For reasons relating to regional stability or surreptitious listening; 
(3) Specially designed and prepared nuclear equipment, parts and components, materials, software, and technology 
covered by part 810 of title 10, Code of Federal Regulations (relating to assistance to foreign atomic energy activities); 
(4) Nuclear facilities, equipment, and material covered by part 110 of title 10, Code of Federal Regulations (relating to 
export and import of nuclear equipment and material); 
(5) Select agents and toxins covered by part 331 of title 7, Code of Federal Regulations, part 121 of title 9 of such 
Code, or part 73 of title 42 of such Code; or 
(6) Emerging and foundational technologies controlled pursuant to section 1758 of the Export Control Reform Act of 
2018 (50 U.S.C. 4817).

Version June 28, 2023 
2024056 
 
 
 
 
Page 52 of 137 
Interconnection arrangements means arrangements governing the physical connection of two or more networks to allow 
the use of another's network to hand off traffic where it is ultimately delivered (e.g., connection of a customer of telephone 
provider A to a customer of telephone company B) or sharing data and other information resources.
Reasonable inquiry means an inquiry designed to uncover any information in the entity's possession about the identity of 
the producer or provider of covered telecommunications equipment or services used by the entity that excludes the need to 
include an internal or third-party audit. 
Roaming means cellular communications services (e.g., voice, video, data) received from a visited network when unable 
to connect to the facilities of the home network either because signal coverage is too weak or because traffic is too high. 
Substantial or essential component means any component necessary for the proper function or performance of a piece of 
equipment, system, or service. 
(b) Prohibition.   
(1) Section 889(a)(1)(A) of the John S. McCain National Defense Authorization Act for Fiscal Year 2019 (Pub. L. 115-232) 
prohibits the head of an executive agency on or after August 13, 2019, from procuring or obtaining, or extending or renewing a 
contract to procure or obtain, any equipment, system, or service that uses covered telecommunications equipment or services as 
a substantial or essential component of any system, or as critical technology as part of any system. The Contractor is prohibited 
from providing to the Government any equipment, system, or service that uses covered telecommunications equipment or 
services as a substantial or essential component of any system, or as critical technology as part of any system, unless an 
exception at paragraph (c) of this clause applies or the covered telecommunication equipment or services are covered by a 
waiver described in FAR 4.2104. 
(2) Section 889(a)(1)(B) of the John S. McCain National Defense Authorization Act for Fiscal Year 2019 (Pub. L. 115-
232) prohibits the head of an executive agency on or after August 13, 2020, from entering into a contract, or extending or 
renewing a contract, with an entity that uses any equipment, system, or service that uses covered telecommunications 
equipment or services as a substantial or essential component of any system, or as critical technology as part of any system, 
unless an exception at paragraph (c) of this clause applies or the covered telecommunication equipment or services are covered 
by a waiver described in FAR 4.2104. This prohibition applies to the use of covered telecommunications equipment or services, 
regardless of whether that use is in performance of work under a Federal contract. 
(c) Exceptions. This clause does not prohibit contractors from providing— 
(1) A service that connects to the facilities of a third-party, such as backhaul, roaming, or interconnection 
arrangements; or 
(2) Telecommunications equipment that cannot route or redirect user data traffic or permit visibility into any user data 
or packets that such equipment transmits or otherwise handles. 
(d) Reporting requirement. 
(1) In the event the Contractor identifies covered telecommunications equipment or services used as a substantial or 
essential component of any system, or as critical technology as part of any system, during contract performance, or the 
Contractor is notified of such by a subcontractor at any tier or by any other source, the Contractor shall report the information in 
paragraph (d)(2) of this clause to the Contracting Officer, unless elsewhere in this contract are established procedures for 
reporting the information; in the case of the Department of Defense, the Contractor shall report to the website 
at https://dibnet.dod.mil. For indefinite delivery contracts, the Contractor shall report to the Contracting Officer for the indefinite 
delivery contract and the Contracting Officer(s) for any affected order or, in the case of the Department of Defense, identify both 
the indefinite delivery contract and any affected orders in the report provided at https://dibnet.dod.mil. 
(2) The Contractor shall report the following information pursuant to paragraph (d)(1) of this clause 
(i) Within one business day from the date of such identification or notification: the contract number; the order 
number(s), if applicable; supplier name; supplier unique entity identifier (if known); supplier Commercial and Government Entity 
(CAGE) code (if known); brand; model number (original equipment manufacturer number, manufacturer part number, or 
wholesaler number); item description; and any readily available information about mitigation actions undertaken or 
recommended. 
(ii) Within 10 business days of submitting the information in paragraph (d)(2)(i) of this clause: any further available 
information about mitigation actions undertaken or recommended. In addition, the Contractor shall describe the efforts it 
undertook to prevent use or submission of covered telecommunications equipment or services, and any additional efforts that will 
be incorporated to prevent future use or submission of covered telecommunications equipment or services.

Version June 28, 2023 
2024056 
Page 78 of 137 
Exhibit G 
New Jersey Business Compliance 
NEW JERSEY BUSINESS COMPLIANCE
Suppliers intending to do business in the State of New Jersey must comply with policies and 
procedures required under New Jersey statues.  All offerors submitting proposals must complete 
the following forms specific to the State of New Jersey.  Completed forms should be submitted 
with the offeror’s response to the RFP.  Failure to complete the New Jersey packet will impact 
OMNIA Partners’ ability to promote the Master Agreement in the State of New Jersey.
DOC #1 
Ownership Disclosure Form 
DOC #2 
Non-Collusion Affidavit 
DOC #3 
Affirmative Action Affidavit 
DOC #4 
Political Contribution Disclosure Form
DOC #5 
Stockholder Disclosure Certification 
DOC #6 
Disclosure of Investment Activities in Iran, Russia and Belarus 
DOC #7 
New Jersey Business Registration Certificate 
DOC #8 
EEOAA Evidence 
DOC #9 
MacBride Principals Form 
New Jersey suppliers are required to comply with the following New Jersey statutes when 
applicable:
all anti-discrimination laws, including those contained in N.J.S.A. 10:2-1 through N.J.S.A.
10:2-14, N.J.S.A. 10:5-1, and N.J.S.A. 10:5-31 through 10:5-38;
Prevailing Wage Act, N.J.S.A. 34:11-56.26, for all contracts within the contemplation of
the Act;
Public Works Contractor Registration Act, N.J.S.A. 34:11-56.26; and
Bid and Performance Security, as required by the applicable municipal or state statutes.

Version June 28, 2023 
2024056 
Page 81 of 137 
DOC #2
NON-COLLUSION AFFIDAVIT 
STANDARD BID DOCUMENT REFERENCE 
Reference: VII-H
Name of Form: 
NON-COLLUSION AFFIDAVIT 
Statutory Reference: 
No specific statutory reference 
State Statutory Reference N.J.S.A. 52:34-15
Instructions Reference: 
Statutory and Other Requirements VII-H 
Description:
The Owner’s use of this form is optional. It is used to ensure 
that the bidder has not participated in any collusion with any 
other bidder or Owner representative or otherwise taken any 
action in restraint of free and competitive bidding.

Version June 28, 2023 
2024056
Page 83 of 137
DOC #3
AFFIRMATIVE ACTION AFFIDAVIT
(P.L. 1975, C.127)
Company Name:  
Street:
City, State, Zip Code:
Proposal Certification:
Indicate below company’s
compliance with New Jersey Affirmative Action regulations. 
Company’s proposal will be accepted even if company is not in compliance at this time. No 
contract and/or purchase order may be issued, however, until all Affirmative Action requirements 
are met.
Required Affirmative Action Evidence:
Procurement, Professional & Service Contracts (Exhibit A)
Vendors must submit with proposal:
1. A photocopy of a valid letter that the contractor is operating under an existing
Federally approved or sanctioned affirmative action program (good for one year from
the date of the letter);
OR
2. A photocopy of a Certificate of Employee Information Report approval, issued in
accordance with N.J.A.C. 17:27-4;
OR
3. A photocopy of an Employee Information Report (Form AA302) provided by the
Division of Contract Compliance and Equal Employment Opportunity in Public
Contracts and distributed to the public agency to be completed by the contractor in
accordance with N.J.A.C. 17:27-4.
Public Work – Over $50,000 Total Project Cost:
A. No approved Federal or New Jersey Affirmative Action Plan. We will complete Report Form
AA201. A project contract ID number will be assigned to your firm upon receipt of the
completed Initial Project Workforce Report (AA201) for this contract.
B. Approved Federal or New Jersey Plan – certificate enclosed
I further certify that the statements and information contained herein, are complete and correct to 
the best of my knowledge and belief. 
_________________
_
______________
Date 
Authorized Signature and Title

Version June 28, 2023 
2024056 
Page 84 of 137

Version June 28, 2023 
2024056 
 
 
 
 
Page 85 of 137 
DOC #3, continued 
 
P.L. 1995, c. 127 (N.J.A.C. 17:27) 
MANDATORY AFFIRMATIVE ACTION LANGUAGE 
 
PROCUREMENT, PROFESSIONAL AND SERVICE 
CONTRACTS 
 
During the performance of this contract, the contractor agrees as follows: 
The contractor or subcontractor, where applicable, will not discriminate against any employee or applicant for 
employment because of age, race, creed, color, national origin, ancestry, marital status, sex, affectional or sexual 
orientation.  The contractor will take affirmative action to ensure that such applicants are recruited and employed, 
and that employees are treated during employment, without regard to their age, race, creed, color, national origin, 
ancestry, marital status, sex, affectional or sexual orientation.  Such action shall include, but not be limited to the 
following:  employment, upgrading, demotion, or transfer; recruitment or recruitment advertising; layoff or 
termination; rates of pay or other forms of compensation; and selection for training, including apprenticeship.  The 
contractor agrees to post in conspicuous places, available to employees and applicants for employment, notices to 
be provided by the Public Agency Compliance Officer setting forth provisions of this non-discrimination clause. 
The contractor or subcontractor, where applicable will, in all solicitations or advertisement for employees placed by 
or on behalf of the contractor, state that all qualified applicants will receive consideration for employment without 
regard to age, race, creed, color, national origin, ancestry, marital status, sex, affectional or sexual orientation. 
The contractor or subcontractor, where applicable, will send to each labor union or representative of workers with 
which it has a collective bargaining agreement or other contract or understanding, a notice, to be provided by the 
agency contracting officer advising the labor union or workers' representative of the contractor's commitments under 
this act and shall post copies of the notice in conspicuous places available to employees and applicants for 
employment. 
The contractor or subcontractor, where applicable, agrees to comply with any regulations promulgated by the 
Treasurer pursuant to P.L. 1975, c. 127, as amended and supplemented from time to time and the Americans with 
Disabilities Act. 
The contractor or subcontractor agrees to attempt in good faith to employ minority and female workers trade 
consistent with the applicable county employment goal prescribed by N.J.A.C. 17:27-5.2 promulgated by the 
Treasurer pursuant to P.L. 1975, C.127, as amended and supplemented from time to time or in accordance with a 
binding determination of the applicable county employment goals determined by the Affirmative Action Office 
pursuant to N.J.A.C. 17:27-5.2 promulgated by the Treasurer pursuant to P.L. 1975, C.127, as amended and 
supplemented from time to time. 
The contractor or subcontractor agrees to inform in writing appropriate recruitment agencies in the area, including 
employment agencies, placement bureaus, colleges, universities, labor unions, that it does not discriminate on the 
basis of age, creed, color, national origin, ancestry, marital status, sex, affectional or sexual orientation, and that it 
will discontinue the use of any recruitment agency which engages in direct or indirect discriminatory practices. 
The contractor or subcontractor agrees to revise any of it testing procedures, if necessary, to assure that all 
personnel testing conforms with the principles of job-related testing, as established by the statutes and court 
decisions of the state of New Jersey and as established by applicable Federal law and applicable Federal court 
decisions. 
The contractor or subcontractor agrees to review all procedures relating to transfer, upgrading, downgrading and 
lay-off to ensure that all such actions are taken without regard to age, creed, color, national origin, ancestry, marital 
status, sex, affectional or sexual orientation, and conform with the applicable employment goals, consistent with the 
statutes and court decisions of the State of New Jersey, and applicable Federal law and applicable Federal court 
decisions. 
The contractor and its subcontractors shall furnish such reports or other documents to the Affirmative Action Office 
as may be requested by the office from time to time in order to carry out the purposes of these regulations, and 
public agencies shall furnish such information as may be requested by the Affirmative Action Office for conducting a 
compliance investigation pursuant to Subchapter 10 of the Administrative Code (NJAC 17:27).

Version June 28, 2023 
2024056
 
 
 
 
Page 86 of 137
______________
_______________
Signature of Procurement Agent

Version June 28, 2023 
2024056 
 
 
 
 
Page 87 of 137 
DOC #4
 
C. 271 POLITICAL CONTRIBUTION DISCLOSURE FORM 
 
Public Agency Instructions 
 
This page provides guidance to public agencies entering into contracts with business entities that are required to file Political 
Contribution Disclosure forms with the agency.  It is not intended to be provided to contractors. What follows are 
instructions on the use of form local units can provide to contractors that are required to disclose political contributions 
pursuant to N.J.S.A. 19:44A-20.26 (P.L. 2005, c. 271, s.2).  Additional information on the process is available in Local Finance 
Notice 2006-1 (http://www.nj.gov/dca/divisions/dlgs/resources/lfns 2006.html). Please refer back to these instructions for the 
appropriate links, as the Local Finance Notices include links that are no longer operational. 
1. The disclosure is required for all contracts in excess of $17,500 that are not awarded pursuant to a “fair and open” process 
(N.J.S.A. 19:44A-20.7). 
2. Due to the potential length of some contractor submissions, the public agency should consider allowing data to be 
submitted in electronic form (i.e., spreadsheet, pdf file, etc.).  Submissions must be kept with the contract documents or in 
an appropriate computer file and be available for public access.  The form is worded to accept this alternate submission.  
The text should be amended if electronic submission will not be allowed. 
3. The submission must be received from the contractor and on file at least 10 days prior to award of the contract.  
Resolutions of award should reflect that the disclosure has been received and is on file. 
4. The contractor must disclose contributions made to candidate and party committees covering a wide range of public 
agencies, including all public agencies that have elected officials in the county of the public agency, state legislative 
positions, and various state entities.  The Division of Local Government Services recommends that contractors be provided 
a list of the affected agencies.  This will assist contractors in determining the campaign and political committees of the 
officials and candidates affected by the disclosure. 
a. 
The Division has prepared model disclosure forms for each county.  They can be downloaded from the “County PCD 
Forms” link on the Pay-to-Play web site at http://www.nj.gov/dca/divisions/dlgs/programs/lpcl.html#12. They will be 
updated from time-to-time as necessary. 
b. A public agency using these forms should edit them to properly reflect the correct legislative district(s).  As the 
forms are county-based, they list all legislative districts in each county.  Districts that do not represent the public 
agency should be removed from the lists. 
c. 
Some contractors may find it easier to provide a single list that covers all contributions, regardless of the county.  
These submissions are appropriate and should be accepted. 
d. The form may be used “as-is”, subject to edits as described herein. 
e. 
The “Contractor Instructions” sheet is intended to be provided with the form.  It is recommended that the Instructions 
and the form be printed on the same piece of paper.  The form notes that the Instructions are printed on the back of the 
form; where that is not the case, the text should be edited accordingly. 
f. 
The form is a Word document and can be edited to meet local needs, and posted for download on web sites, used as an 
e-mail attachment, or provided as a printed document. 
 
5. It is recommended that the contractor also complete a “Stockholder Disclosure Certification.”  This will assist the local unit 
in its obligation to ensure that contractor did not make any prohibited contributions to the committees listed on the 
Business Entity Disclosure Certification in the 12 months prior to the contract  (See Local Finance Notice 2006-7 for 
additional information on this obligation at http://www.nj.gov/dca/divisions/dlgs/resources/lfns_2006.html).  A sample 
Certification form is part of this package and the instruction to complete it is included in the Contractor Instructions.  
NOTE:  This section is not applicable to Boards of Education.

Version June 28, 2023 
2024056 
 
 
 
 
Page 88 of 137 
DOC #4, continued 
C. 271 POLITICAL CONTRIBUTION DISCLOSURE FORM 
 
Contractor Instructions 
 
Business entities (contractors) receiving contracts from a public agency that are NOT awarded pursuant to a “fair and open” 
process (defined at N.J.S.A. 19:44A-20.7) are subject to the provisions of P.L. 2005, c. 271, s.2 (N.J.S.A. 19:44A-20.26).  This 
law provides that 10 days prior to the award of such a contract, the contractor shall disclose contributions to:  
 
any State, county, or municipal committee of a political party 
 
any legislative leadership committee* 
 
any continuing political committee (a.k.a., political action committee) 
 
any candidate committee of a candidate for, or holder of, an elective office: 
o 
of the public entity awarding the contract 
o 
of that county in which that public entity is located 
o 
of another public entity within that county 
o 
or of a legislative district in which that public entity is located or, when the public entity is a county, of any 
legislative district which includes all or part of the county 
 
The disclosure must list reportable contributions to any of the committees that exceed $300 per election cycle that 
were made during the 12 months prior to award of the contract.  See N.J.S.A. 19:44A-8 and 19:44A-16 for more 
details on reportable contributions. 
 
N.J.S.A. 19:44A-20.26 itemizes the parties from whom contributions must be disclosed when a business entity is 
not a natural person.  This includes the following: 
 
individuals with an “interest” ownership or control of more than 10% of the profits or assets of a business entity or 
10% of the stock in the case of a business entity that is a corporation for profit 
 
all principals, partners, officers, or directors of the business entity or their spouses 
 
any subsidiaries directly or indirectly controlled by the business entity 
 
IRS Code Section 527 New Jersey based organizations, directly or indirectly controlled by the business entity and 
filing as continuing political committees, (PACs). 
 
When the business entity is a natural person, “a contribution by that person’s spouse or child, residing therewith, 
shall be deemed to be a contribution by the business entity.” [N.J.S.A. 19:44A-20.26(b)] The contributor must be 
listed on the disclosure. 
 
Any business entity that fails to comply with the disclosure provisions shall be subject to a fine imposed by ELEC in 
an amount to be determined by the Commission which may be based upon the amount that the business entity 
failed to report. 
 
The enclosed list of agencies is provided to assist the contractor in identifying those public agencies whose elected 
official and/or candidate campaign committees are affected by the disclosure requirement.  It is the contractor’s 
responsibility to identify the specific committees to which contributions may have been made and need to be 
disclosed.  The disclosed information may exceed the minimum requirement. 
 
The enclosed form, a content-consistent facsimile, or an electronic data file containing the required details (along 
with a signed cover sheet) may be used as the contractor’s submission and is disclosable to the public under the 
Open Public Records Act. 
 
The contractor must also complete the attached Stockholder Disclosure Certification.  This will assist the agency in 
meeting its obligations under the law. NOTE:  This section does not apply to Board of Education contracts. 
 
* N.J.S.A. 19:44A-3(s):  “The term "legislative leadership committee" means a committee established, authorized to 
be established, or designated by the President of the Senate, the Minority Leader of the Senate, the Speaker of the 
General Assembly or the Minority Leader of the General Assembly pursuant to section 16 of P.L.1993, c.65 
(C.19:44A-10.1) for the purpose of receiving contributions and making expenditures.”

Version June 28, 2023 
2024056 
 
 
 
 
Page 93 of 137 
DOC #7
 
NEW JERSEY BUSINESS REGISTRATION CERTIFICATE
(N.J.S.A. 52:32-44) 
Offerors wishing to do business in New Jersey must submit their State Division of Revenue 
issued Business Registration Certificate with their proposal here. Failure to do so will disqualify 
the Offeror from offering products or services in New Jersey through any resulting contract. 
 
https://www.njportal.com/DOR/BusinessRegistration/

Version June 28, 2023 
2024056 
 
 
 
 
Page 60 of 137 
FEMA AND ADDITIONAL FEDERAL FUNDING SPECIAL CONDITIONS 
 
Awarded Supplier(s) (also referred to as Contractors) may need to respond to events and losses where 
products and services are needed for the immediate and initial response to emergency situations such 
as, but not limited to, water damage, fire damage, vandalism cleanup, biohazard cleanup, sewage 
decontamination, deodorization, and/or wind damage during a disaster or emergency situation. By 
submitting a proposal, the Supplier is accepted these FEMA and Additional Federal Funding Special 
Conditions required by the Federal Emergency Management Agency (FEMA) and other federal entities.  
 
“Contract” in the below pages under FEMA AND ADDITIONAL FEDERAL FUNDING SPECIAL 
CONDITIONS is also referred to and defined as the “Master Agreement”. 
 
“Contractor” in the below pages under FEMA AND ADDITIONAL FEDERAL FUNDING SPECIAL 
CONDITIONS is also referred to and defined as “Supplier” or “Awarded Supplier”. 
 
Conflicts of Interest 
No employee, officer, or agent may participate in the selection, award, or administration of a contract 
supported by a FEMA award if he or she has a real or apparent conflict of interest. Such a conflict would 
arise when the employee, officer, or agent, any member of his or her immediate family, his or her partner, 
or an organization which employs or is about to employ any of these parties, has a financial or other 
interest in or a tangible personal benefit from a firm considered for award. 2 C.F.R. § 200.318(c)(1); See 
also Standard Form 424D, ¶ 7; Standard Form 424B, ¶ 3. i. FEMA considers a “financial interest” to be 
the potential for gain or loss to the employee, officer, or agent, any member of his or her immediate 
family, his or her partner, or an organization which employs or is about to employ any of these parties as 
a result of the particular procurement. The prohibited financial interest may arise from ownership of 
certain financial instruments or investments such as stock, bonds, or real estate, or from a salary, 
indebtedness, job offer, or similar interest that might be affected by the particular procurement. ii. FEMA 
considers an “apparent” conflict of interest to exist where an actual conflict does not exist, but where a 
reasonable person with knowledge of the relevant facts would question the impartiality of the employee, 
officer, or agent participating in the procurement. c. Gifts. The officers, employees, and agents of the 
Participating Public Agency nor the Participating Public Agency (“NFE”) must neither solicit nor accept 
gratuities, favors, or anything of monetary value from contractors or parties to subcontracts. However, 
NFE’s may set standards for situations in which the financial interest is de minimus, not substantial, or the 
gift is an unsolicited item of nominal value. 2 C.F.R. § 200.318(c)(1). d. Violations. The NFE’s written 
standards of conduct must provide for disciplinary actions to be applied for violations of such standards 
by officers, employees, or agents of the NFE. 2 C.F.R. § 200.318(c)(1). For example, the penalty for a 
NFE’s employee may be dismissal, and the penalty for a contractor might be the termination of the 
contract. 
Contractor Integrity 
A contractor must have a satisfactory record of integrity and business ethics. Contractors that are 
debarred or suspended, as described in and subject to the debarment and suspension regulations 
implementing Executive Order 12549, Debarment and Suspension (1986) and Executive Order 12689, 
Debarment and Suspension (1989) at 2 C.F.R. Part 180 and the Department of Homeland Security’s 
regulations at 2 C.F.R. Part 3000 (Non-procurement Debarment and Suspension), must be rejected and 
cannot receive contract awards at any level. 
 
Notice of Legal Matters Affecting the Federal Government  
In the event FTA or DOT funding is used by Participating Public Agency, Contractor agrees to: 
1) The Contractor agrees that if a current or prospective legal matter that may affect the Federal 
Government emerges, the Contractor shall promptly notify the Participating Public Agency of the 
legal matter in accordance with 2 C.F.R. §§ 180.220 and 1200.220.

Version June 28, 2023 
2024056 
 
 
 
 
Page 61 of 137 
2) The types of legal matters that require notification include, but are not limited to, a major dispute, 
breach, default, litigation, or naming the Federal Government as a party to litigation or a legal 
disagreement in any forum for any reason. 
 
3) The Contractor further agrees to include the above clause in each subcontract, at every tier, 
financed in whole or in part with Federal assistance provided by the FTA. 
 
Public Policy 
A contractor must comply with the public policies of the Federal Government and state, local government, 
or tribal government. This includes, among other things, past and current compliance with the:  
a. Equal opportunity and nondiscrimination laws  
b. Five affirmative steps described at 2 C.F.R. § 200.321(b) for all subcontracting under contracts 
supported by FEMA financial assistance; and FEMA Procurement Guidance June 21, 2016 Page IV- 7  
c. Applicable prevailing wage laws, regulations, and executive orders  
 
Affirmative Steps 
For any subcontracting opportunities, Contractor must take the following Affirmative steps: 
1. Placing qualified small and minority businesses and women's business enterprises on solicitation 
lists; 
2. Assuring that small and minority businesses, and women's business enterprises are solicited 
whenever they are potential sources; 
3. Dividing total requirements, when economically feasible, into smaller tasks or quantities to permit 
maximum participation by small and minority businesses, and women's business enterprises; 
4. Establishing delivery schedules, where the requirement permits, which encourage participation by 
small and minority businesses, and women's business enterprises; and 
5. Using the services and assistance, as appropriate, of such organizations as the Small Business 
Administration and the Minority Business Development Agency of the Department of Commerce. 
Prevailing Wage Requirements 
When applicable, the awarded Contractor (s) and any and all subcontractor(s) agree to comply with all 
laws regarding prevailing wage rates including the Davis-Bacon Act, applicable to this solicitation and/or 
Participating Public Agencies.  The Participating Public Agency shall notify the Contractor of the 
applicable pricing/prevailing wage rates and must apply any local wage rates requested. The Contractor 
and any subcontractor(s) shall comply with the prevailing wage rates set by the Participating Public 
Agency.  
 
Federal Requirements
If products and services are issued in response to an emergency or disaster recovery the items below, 
located in this FEMA Special Conditions section of the Federal Funds Certifications, are activated and 
required when federal funding may be utilized. 
2 C.F.R. § 200.326 and 2 C.F.R. Part 200, Appendix II, Required Contract Clauses 
1. 
CONTRACT REMEDIES 
Contracts for more than the federal simplified acquisition threshold (SAT), the dollar amount 
below which an NFE may purchase property or services using small purchase methods, 
currently set at $250,000 for procurements made on or after June 20, 2018,4 must address 
administrative, contractual, or legal remedies in instances where contractors violate or breach 
contract terms and must provide for sanctions and penalties as appropriate.  
 
1.1 Applicability

Version June 28, 2023 
2024056 
 
 
 
 
Page 62 of 137 
This contract provision is required for contracts over the SAT, currently set at $250,000 for 
procurements made on or after June 20, 2018. Although not required for contracts at or below 
the SAT, FEMA suggests including a remedies provision.

Version June 28, 2023 
2024056 
 
 
 
 
Page 63 of 137 
1.2 Additional Considerations  
For FEMA’s Assistance to Firefighters Grant (AFG) Program, recipients must include a penalty 
clause in all contracts for any AFG-funded vehicle, regardless of dollar amount. In that situation, 
the contract must include a clause addressing that non-delivery by the contract’s specified date 
or other vendor nonperformance will require a penalty of no less than $100 per day until such 
time that the vehicle, compliant with the terms of the contract, has been accepted by the 
recipient. This penalty clause should, however, account for force majeure or acts of God. AFG 
recipients should refer to the applicable year’s Notice of Funding Opportunity (NOFO) for 
additional information, which can be accessed at FEMA.gov. 
 
2.
TERMINATION FOR CAUSE AND CONVENIENCE
 
a. 
Standard. All contracts in excess of $10,000 must address termination for cause and for 
convenience by the non-Federal entity, including the manner by which it will be effected 
and the basis for settlement. See 2 C.F.R. Part 200, Appendix II(B). 
b.
Applicability. This requirement applies to all FEMA grant and cooperative agreement 
programs. 
3. 
EQUAL EMPLOYMENT OPPORTUNITY 
 
When applicable: 
 
a.
Standard. Except as otherwise provided under 41 C.F.R. Part 60, all contracts that 
meet the definition of “federally assisted construction contract” in 41 C.F.R. 
§ 60-1.3 must include the equal opportunity clause provided under 41 C.F.R. § 60- 
1.4(b), in accordance with Executive Order 11246, Equal Employment Opportunity (30 
Fed. Reg. 12319, 12935, 3 C.F.R. Part, 1964-1965 Comp., p. 
339), as amended by Executive Order 11375, Amending Executive Order 11246 
Relating to Equal Employment Opportunity, and implementing regulations at 41 
C.F.R. Part 60 (Office of Federal Contract Compliance Programs, Equal Employment 
Opportunity, Department of Labor). See 2 C.F.R. Part 200, Appendix II(C). 
 
b. Key Definitions. 
i. 
Federally Assisted Construction Contract. The regulation at 41 C.F.R. § 60- 
1.3 defines a “federally assisted construction contract” as any agreement or 
modification thereof between any applicant and a person for construction work 
which is paid for in whole or in part with funds obtained from the Government or 
borrowed on the credit of the Government pursuant to any Federal program 
involving a grant, contract, loan, insurance, or guarantee, or undertaken pursuant to 
any Federal program involving such grant, contract, loan, insurance, or guarantee, 
or any application or modification thereof approved by the Government for a grant, 
contract, loan, insurance, or guarantee under which the applicant itself participates 
in the construction work. 
 
ii. 
Construction Work. The regulation at 41 C.F.R. § 60-1.3 defines “construction work” 
as the construction, rehabilitation, alteration, conversion, extension, demolition or 
repair of buildings, highways, or other changes or improvements to real property,

Version June 28, 2023 
2024056 
 
 
 
 
Page 64 of 137 
iii. including facilities providing utility services. The term also includes the supervision, 
inspection, and other onsite functions incidental to the actual construction. 
 
c. 
Applicability. This requirement applies to all FEMA grant and cooperative agreement 
programs. 
d.
Required Language. The regulation at 41 C.F.R. Part 60-1.4(b) requires the insertion of 
the following contract clause. 
During the performance of this contract, the contractor agrees as follows: 
(1) The contractor will not discriminate against any employee or applicant for 
employment because of race, color, religion, sex, sexual orientation, gender identity, or 
national origin. The contractor will take affirmative action to ensure that applicants are 
employed, and that employees are treated during employment without regard to their 
race, color, religion, sex, sexual orientation, gender identity, or national origin. Such 
action shall include, but not be limited to the following: 
Employment, upgrading, demotion, or transfer; recruitment or recruitment advertising; 
layoff or termination; rates of pay or other forms of compensation; and selection for 
training, including apprenticeship. The contractor agrees to post in conspicuous places, 
available to employees and applicants for employment, notices to be provided setting 
forth the provisions of this nondiscrimination clause. 
(2) The contractor will, in all solicitations or advertisements for employees placed by or 
on behalf of the contractor, state that all qualified applicants will receive consideration 
for employment without regard to race, color, religion, sex, sexual orientation, gender 
identity, or national origin. 
(3) The contractor will not discharge or in any other manner discriminate against any 
employee or applicant for employment because such employee or applicant has 
inquired about, discussed, or disclosed the compensation of the employee or applicant 
or another employee or applicant. This provision shall not apply to instances in which 
an employee who has access to the compensation information of other employees or 
applicants as a part of such employee's essential job functions discloses the 
compensation of such other employees or applicants to individuals who do not 
otherwise have access to such information, unless such disclosure is in response to a 
formal complaint or charge, in furtherance of an investigation, proceeding, hearing, or 
action, including an investigation conducted by the employer, or is consistent with the 
contractor's legal duty to furnish information. 
 
(4) The contractor will send to each labor union or representative of workers with 
which he has a collective bargaining agreement or other contract or understanding, a 
notice to be provided advising the said labor union or workers' representatives of the 
contractor's commitments under this section and shall post copies of the notice in 
conspicuous places available to employees and applicants for employment. 
(5) The contractor will comply with all provisions of Executive Order 11246 of 
September 24, 1965, and of the rules, regulations, and relevant orders of the Secretary 
of Labor. 
(6) The contractor will furnish all information and reports required by Executive Order 
11246 of September 24, 1965, and by rules, regulations, and orders of the Secretary of 
Labor, or pursuant thereto, and will permit access to his books, records, and accounts 
by the administering agency and the Secretary of Labor for purposes of investigation to

Version June 28, 2023 
2024056 
 
 
 
 
Page 65 of 137 
ascertain compliance with such rules, regulations, and orders. 
(7) In the event of the contractor's noncompliance with the nondiscrimination clauses 
of this contract or with any of the said rules, regulations, or orders, this contract may be 
canceled, terminated, or suspended in whole or in part and the contractor may be 
declared ineligible for further Government contracts or federally assisted construction 
contracts in accordance with procedures authorized in Executive Order 11246 of 
September 24, 1965, and such other sanctions may be imposed and remedies invoked 
as provided in Executive Order 11246 of September 24, 1965, or by rule, regulation, or 
order of the Secretary of Labor, or as otherwise provided by law. 
(8) The contractor will include the portion of the sentence immediately preceding 
paragraph (1) and the provisions of paragraphs (1) through (8) in every subcontract or 
purchase order unless exempted by rules, regulations, or orders of the Secretary of 
Labor issued pursuant to section 204 of Executive Order 11246 of September 24, 
1965, so that such provisions will be binding upon each subcontractor or vendor. The 
contractor will take such action with respect to any subcontract or purchase order as 
the administering agency may direct as a means of enforcing such provisions, including 
sanctions for noncompliance:  
Provided, however, that in the event a contractor becomes involved in, or is threatened 
with, litigation with a subcontractor or vendor as a result of such direction by the 
administering agency, the contractor may request the United States to enter into such 
litigation to protect the interests of the United States. 
The applicant further agrees that it will be bound by the above equal opportunity clause 
with respect to its own employment practices when it participates in federally assisted 
construction work: Provided, That if the applicant so participating is a State or local 
government, the above equal opportunity clause is not applicable to any agency, 
instrumentality or subdivision of such government which does not participate in work 
on or under the contract. 
The applicant agrees that it will assist and cooperate actively with the administering 
agency and the Secretary of Labor in obtaining the compliance of contractors and 
subcontractors with the equal opportunity clause and the rules, regulations, and 
relevant orders of the Secretary of Labor, that it will furnish the administering agency 
and the Secretary of Labor such information as they may require for the supervision of 
such compliance, and that it will otherwise assist the administering agency in the 
discharge of the agency's primary responsibility for securing compliance. 
The applicant further agrees that it will refrain from entering into any contract or 
contract modification subject to Executive Order 11246 of September 24, 1965, with a 
contractor debarred from, or who has not demonstrated eligibility for, Government 
contracts and federally assisted construction contracts pursuant to the Executive Order 
and will carry out such sanctions and penalties for violation of the equal opportunity 
clause as may be imposed upon contractors and subcontractors by the administering 
agency or the Secretary of Labor pursuant to Part II, Subpart D of the Executive Order. 
In addition, the applicant agrees that if it fails or refuses to comply with these 
undertakings, the administering agency may take any or all of the following actions: 
Cancel, terminate, or suspend in whole or in part this grant (contract, loan, insurance, 
guarantee); refrain from extending any further assistance to the applicant under the 
program with respect to which the failure or refund occurred until satisfactory 
assurance of future compliance has been received from such applicant; and refer the 
case to the Department of Justice for appropriate legal proceedings.

Version June 28, 2023 
2024056 
 
 
 
 
Page 66 of 137 
4. 
DAVIS-BACON ACT 
 
a. 
Standard. All prime construction contracts in excess of $2,000 awarded by non- Federal 
entities must include a provision for compliance with the Davis-Bacon Act (40 U.S.C. §§ 
3141-3144 and 3146-3148) as supplemented by Department of Labor regulations at 29 
C.F.R. Part 5 (Labor Standards Provisions Applicable to Contracts Covering Federally 
Financed and Assisted Construction). See 2 C.F.R. Part 200, Appendix II(D). In accordance 
with the statute, contractors must be required to pay wages to laborers and mechanics at a 
rate not less than the prevailing wages specified in a wage determination made by the 
Secretary of Labor. In addition, contractors must be required to pay wages not less than 
once a week. 
b.
Applicability. The Davis-Bacon Act applies to the Emergency Management Preparedness 
Grant Program, Homeland Security Grant Program, Nonprofit Security Grant Program, Tribal 
Homeland Security Grant Program, Port Security Grant Program, and Transit Security 
Grant Program.  
c.
Requirements. If applicable, the non-federal entity must do the following: 
i. The non-Federal entity must place a copy of the current prevailing wage 
determination issued by the Department of Labor in each solicitation. The 
decision to award a contract or subcontract must be conditioned upon the 
acceptance of the wage determination. The non-Federal entity must report all 
suspected or reported violations to the Federal awarding agency. 
ii. Additionally, pursuant 2 C.F.R. Part 200, Appendix II(D), contracts subject to the 
Davis-Bacon Act, must also include a provision for compliance  with the 
Copeland “Anti-Kickback” Act (40 U.S.C. § 3145), as supplemented by 
Department of Labor regulations at 29 C.F.R. Part 3 (Contractors and 
Subcontractors on Public Building or Public Work Financed in Whole or in Part 
by Loans or Grants from the United States). The Copeland Anti- Kickback Act 
provides that each contractor or subrecipient must be prohibited from inducing, 
by any means, any person employed in the construction, completion, or repair of 
public work, to give up any part of the compensation to which he or she is 
otherwise entitled. The non- Federal entity must report all suspected or reported 
violations to FEMA. 
 
iii. 
Include a provision for compliance with the Davis-Bacon Act (40 U.S.C. 3141-
3144, and 3146-3148) as supplemented by Department of Labor regulations (29 
CFR Part 5, “Labor Standards Provisions Applicable to Contracts Covering 
Federally Financed and Assisted Construction”). 
 
Suggested Language. The following provides a sample contract clause:  
Compliance with the Davis-Bacon Act. 
a. 
All transactions regarding this contract shall be done in 
compliance with the Davis-Bacon Act (40 U.S.C. 3141- 3144, 
and 3146-3148) and the requirements of 29 C.F.R. pt. 5 as may 
be applicable. The contractor shall comply with 40 U.S.C. 3141-
3144, and 3146-3148 and the requirements of 29 C.F.R. pt. 5 
as applicable.

Version June 28, 2023 
2024056 
 
 
 
 
Page 67 of 137 
b. Contractors are required to pay wages to laborers and 
mechanics at a rate not less than the prevailing wages specified 
in a wage determination made by the Secretary of Labor. 
 
c. 
Additionally, contractors are required to pay wages not less than 
once a week. 
 
5. 
COPELAND ANTI-KICKBACK ACT 
 
a. 
Standard. Recipient and subrecipient contracts must include a provision for compliance with 
the Copeland “Anti-Kickback” Act (40 U.S.C. 3145), as supplemented by Department of 
Labor regulations (29 CFR Part 3, “Contractors and Subcontractors on Public Building or 
Public Work Financed in Whole or in Part by Loans or Grants from the United States”). 
b.
Applicability. This requirement applies to all contracts for construction or repair work above 
$2,000 in situations where the Davis-Bacon Act also applies. It DOES NOT apply to the 
FEMA Public Assistance Program. 
c.
Requirements. If applicable, the non-federal entity must include a provision for compliance 
with the Copeland “Anti-Kickback” Act (40 U.S.C. § 3145), as supplemented by Department 
of Labor regulations at 29 C.F.R. Part 3 (Contractors and Subcontractors on Public Building 
or Public Work Financed in Whole or in Part by Loans or Grants from the United States). 
Each contractor or subrecipient must be prohibited from inducing, by any means, any 
person employed in the construction, completion, or repair of public work, to give up any 
part of the compensation to which he or she is otherwise entitled. The non-Federal entity 
must report all suspected or reported violations to FEMA. Additionally, in accordance with 
the regulation, each contractor and subcontractor must furnish each week a statement with 
respect to the wages paid each of its employees engaged in work covered by the Copeland 
Anti-Kickback Act and the Davis Bacon Act during the preceding weekly payroll period. The 
report shall be delivered by the contractor or subcontractor, within seven days after the 
regular payment date of the payroll period, to a representative of a Federal or State agency 
in charge at the site of the building or work. 
Sample Language. The following provides a sample contract clause: 
Compliance with the Copeland “Anti-Kickback” Act. 
a. 
Contractor. The contractor shall comply with 18 U.S.C. § 874, 40 
U.S.C. § 3145, and the requirements of 29 C.F.R. pt. 3 as may be 
applicable, which are incorporated by reference into this contract. 
 
b.
Subcontracts. The contractor or subcontractor shall insert in any 
subcontracts the clause above and such other clauses as FEMA may 
by appropriate instructions require, and also a clause requiring the 
subcontractors to include these clauses in any lower tier subcontracts. 
The prime contractor shall be responsible for the compliance by any 
subcontractor or lower tier subcontractor with all of these contract 
clauses. 
 
c. 
Breach. A breach of the contract clauses above may be grounds for 
termination of the contract, and for debarment as a contractor and 
subcontractor as provided in 29 C.F.R. §5.12.”

Version June 28, 2023 
2024056 
 
 
 
 
Page 68 of 137 
6. 
CONTRACT WORK HOURS AND SAFETY STANDARDS ACT 
 
a. 
Standard. Where applicable (see 40 U.S.C. §§ 3701-3708), all contracts awarded by 
the non-Federal entity in excess of $100,000 that involve the employment of mechanics 
or laborers must include a provision for compliance with 40 U.S.C. §§ 3702 and 3704, 
as supplemented by Department of Labor regulations at 29 C.F.R. Part 5. See 2 C.F.R. 
Part 200, Appendix II(E). Under 40 U.S.C. § 3702, each contractor must be required to 
compute the wages of every mechanic and laborer on the basis of a standard work 
week of 40 hours. Work in excess of the standard work week is permissible provided 
that the worker is compensated at a rate of not less than one and a half times the basic 
rate of pay for all hours worked in excess of 40 hours in the work week. Further, no 
laborer or mechanic must be required to work in surroundings or under working 
conditions which are unsanitary, hazardous, or dangerous. 
b. 
Applicability. This requirement applies to all FEMA contracts awarded by the non- federal 
entity in excess of $100,000 under grant and cooperative agreement programs that 
involve the employment of mechanics or laborers. It is applicable to construction work. 
These requirements do not apply to the purchase of supplies or materials or articles 
ordinarily available on the open market, or contracts for transportation or transmission 
of intelligence. 
c. 
Suggested Language. The regulation at 29 C.F.R. § 5.5(b) provides contract clause 
language concerning compliance with the Contract Work Hours and Safety Standards 
Act. FEMA suggests including the following contract clause: 
Compliance with the Contract Work Hours and Safety Standards Act. 
(1) Overtime requirements. No contractor or subcontractor contracting for any part of 
the contract work which may require or involve the employment of laborers or 
mechanics shall require or permit any such laborer or mechanic in any workweek in 
which he or she is employed on such work to work in excess of forty hours in such 
workweek unless such laborer or mechanic receives compensation at a rate not less 
than one and one-half times the basic rate of pay for all hours worked in excess of forty 
hours in such workweek. 
 
(2) Violation; liability for unpaid wages; liquidated damages. In the event of any 
violation of the clause set forth in paragraph (b)(1) of this section the contractor and 
any subcontractor responsible therefor shall be liable for the unpaid wages. In addition, 
such contractor and subcontractor shall be liable to the United States (in the case of 
work done under contract for the District of Columbia or a territory, to such District or to 
such territory), for liquidated damages. Such liquidated damages shall be computed 
with respect to each individual laborer or mechanic, including watchmen and guards, 
employed in violation of the clause set forth in paragraph (b)(1) of this section, in the 
sum of $27 for each calendar day on which such individual was required or permitted to 
work in excess of the standard workweek of forty hours without payment of the 
overtime wages required by the clause set forth in paragraph (b)(1) of this section. 
(3) Withholding for unpaid wages and liquidated damages. The Federal agency or 
loan/grant recipient shall upon its own action or upon written request of an authorized 
representative of the Department of Labor withhold or cause to be withheld, from any 
moneys payable on account of work performed by the contractor or subcontractor 
under any such contract or any other Federal contract with the same prime contractor, 
or any other federally-assisted contract subject to the Contract Work Hours and Safety 
Standards Act, which is held by the same prime contractor, such sums as may be 
determined to be necessary to satisfy any liabilities of such contractor or subcontractor

Version June 28, 2023 
2024056 
 
 
 
 
Page 69 of 137 
for unpaid wages and liquidated damages as provided in the clause set forth in 
paragraph (b)(2) of this section. 
(4) Subcontracts. The contractor or subcontractor shall insert in any subcontracts the 
clauses set forth in paragraph (b)(1) through (4) of this section and also a clause 
requiring the subcontractors to include these clauses in any lower tier subcontracts. 
The prime contractor shall be responsible for compliance by any subcontractor or lower 
tier subcontractor with the clauses set forth in paragraphs (b)(1) through (4) of this 
section. 
 
7. 
RIGHTS TO INVENTIONS MADE UNDER A CONTRACT OR AGREEMENT 
 
a. 
Standard. If the FEMA award meets the definition of “funding agreement” under 
37C.F.R. § 401.2(a) and the non-Federal entity wishes to enter into a contract with a 
small business firm or nonprofit organization regarding the substitution of parties, 
assignment or performance of experimental, developmental, or research work under 
that “funding agreement,” the non- Federal entity must comply with the requirements of 
37 C.F.R. Part 401 (Rights to Inventions Made by Nonprofit Organizations and Small 
Business Firms Under Government Grants, Contracts and Cooperative Agreements), 
and any implementing regulations issued by FEMA. See 2 C.F.R. Part 200, Appendix 
II(F). 
b. 
Applicability. This requirement applies to “funding agreements,” but it DOES NOT apply 
to the Public Assistance, Hazard Mitigation Grant Program, Fire Management 
Assistance Grant Program, Crisis Counseling Assistance and Training Grant Program, 
Disaster Case Management Grant Program, and Federal Assistance to Individuals and 
Households – Other Needs Assistance Grant Program, as FEMA awards under these 
programs do not meet the definition of “funding agreement.” 
c. 
Funding Agreements Definition. The regulation at 37 C.F.R. § 401.2(a) defines “funding 
agreement” as any contract, grant, or cooperative agreement entered into between any 
Federal agency, other than the Tennessee Valley Authority, and any contractor for the 
performance of experimental, developmental, or research work funded in whole or in 
part by the Federal government. This term also includes any assignment, substitution of 
parties, or subcontract of any type entered into for the performance of experimental, 
developmental, or research work under a funding agreement as defined in the first 
sentence of this paragraph. 
8. 
CLEAN AIR ACT AND THE FEDERAL WATER POLLUTION CONTROL ACT 
 
a.
Standard. If applicable, contracts must contain a provision that requires the contractor 
to agree to comply with all applicable standards, orders, or regulations issued pursuant 
to the Clean Air Act (42 U.S.C. §§ 7401-7671q.) and the Federal Water Pollution Control 
Act as amended (33 U.S.C. §§ 1251-1387). Violations must be reported to FEMA and 
the Regional Office of the Environmental Protection Agency. See 2 C.F.R. Part 200, 
Appendix II(G). 
b. 
Applicability. This requirement applies to contracts awarded by a non-federal entity of 
amounts in excess of $150,000 under a federal grant. 
c. 
Suggested Language. The following provides a sample contract clause. 
Clean Air Act

Version June 28, 2023 
2024056 
 
 
 
 
Page 70 of 137 
1.
The contractor agrees to comply with all applicable standards, orders or 
regulations issued pursuant to the Clean Air Act, as amended, 42 U.S.C. 
§ 7401 et seq. 
 
2. The contractor agrees to report each violation to the Participating Public 
Agency and understands and agrees that the Participating Public 
Agency will, in turn, report each violation as required to assure 
notification to the Federal Emergency Management Agency, and the 
appropriate Environmental Protection Agency Regional Office. 
 
3. The contractor agrees to include these requirements in each subcontract 
exceeding $150,000 financed in whole or in part with Federal assistance 
provided by FEMA. 
 
Federal Water Pollution Control Act
1. The contractor agrees to comply with all applicable standards, orders, or 
regulations issued pursuant to the Federal Water Pollution Control Act, 
as amended, 33 U.S.C. 1251 et seq. 
 
2. The contractor agrees to report each violation to the Participating Public 
Agency and understands and agrees that the Participating Public 
Agency will, in turn, report each violation as required to assure 
notification to the Federal Emergency Management Agency, and the 
appropriate Environmental Protection Agency Regional Office. 
 
3. The contractor agrees to include these requirements in each subcontract 
exceeding $150,000 financed in whole or in part with Federal assistance 
provided by FEMA. 
 
9. 
DEBARMENT AND SUSPENSION 
 
a. 
Standard. Non-Federal entities and contractors are subject to the debarment and 
suspension regulations implementing Executive Order 12549, Debarment and 
Suspension (1986) and Executive Order 12689, Debarment and Suspension (1989) at 
2 C.F.R. Part 180 and the Department of Homeland Security’s regulations at 2 C.F.R. 
Part 3000 (Non-procurement Debarment and Suspension). 
b. 
Applicability. This requirement applies to all FEMA grant and cooperative 
agreement programs. 
 
c. 
Requirements. 
i. 
These regulations restrict awards, subawards, and contracts with certain parties 
that are debarred, suspended, or otherwise excluded from or ineligible for 
participation in Federal assistance programs and activities. See 2 C.F.R. Part 
200, Appendix II(H); and 2 C.F.R. § 200.213. A contract award must not be 
made to parties listed in the SAM Exclusions. SAM Exclusions is the list 
maintained by the General Services Administration that contains the names of 
parties debarred, suspended, or otherwise excluded by agencies, as well as 
parties declared ineligible under statutory or regulatory authority other than 
Executive Order 12549. SAM exclusions can be accessed at www.sam.gov. See 
2 C.F.R. § 180.530.

Version June 28, 2023 
2024056 
 
 
 
 
Page 71 of 137 
 
ii. 
In general, an “excluded” party cannot receive a Federal grant award or a contract 
within the meaning of a “covered transaction,” to include subawards and 
subcontracts. This includes parties that receive Federal funding indirectly, such 
as contractors to recipients and subrecipients. The key to the exclusion is 
whether there is a “covered transaction,” which is any non-procurement 
transaction (unless excepted) at either a “primary” or “secondary” tier. Although 
“covered transactions” do not include contracts awarded by the Federal 
Government for purposes of the non-procurement common rule and DHS’s 
implementing regulations, it does include some contracts awarded by recipients 
and subrecipients. 
 
iii.
Specifically, a covered transaction includes the following contracts for goods or 
services: 
 
1. 
The contract is awarded by a recipient or subrecipient in the amount of at 
least $25,000. 
 
2. 
The contract requires the approval of FEMA, regardless of amount. 
 
3. 
The contract is for federally-required audit services. 
 
4. 
A subcontract is also a covered transaction if it is awarded by the 
contractor of a recipient or subrecipient and requires either the approval 
of FEMA or is in excess of $25,000. 
 
d. 
Suggested Language. The following provides a debarment and suspension clause. It 
incorporates an optional method of verifying that contractors are not excluded or 
disqualified. 
Suspension and Debarment 
(1) 
This contract is a covered transaction for purposes of 2 C.F.R. pt. 180 and 2 
C.F.R. pt. 3000. As such, the contractor is required to verify that none of the 
contractor’s principals (defined at 2 C.F.R. § 180.995) or its affiliates (defined at 2 
C.F.R. § 180.905) are excluded (defined at 2 C.F.R. § 180.940) or disqualified 
(defined at 2 C.F.R. § 180.935). 
 
(2) 
The contractor must comply with 2 C.F.R. pt. 180, subpart C and2 C.F.R. pt. 
3000, subpart C, and must include a requirement to comply with these 
regulations in any lower tier covered transaction it enters into. 
 
(3) 
This certification is a material representation of fact relied upon by the 
Participating Public Agency. If it is later determined that the contractor did not 
comply with 2 C.F.R. pt. 180, subpart C and 2 C.F.R. pt. 3000, subpart C, in 
addition to remedies available to the Participating Public Agency, the Federal 
Government may pursue available remedies, including but not limited to 
suspension and/or debarment. 
 
(4) 
The bidder or proposer agrees to comply with the requirements of 2 C.F.R. pt. 
180, subpart C and 2 C.F.R. pt. 3000, subpart C while this offer is valid and 
throughout the period of any contract that may arise from this offer. The bidder or 
proposer further agrees to include a provision requiring such compliance in its 
lower tier covered transactions.

Version June 28, 2023 
2024056 
 
 
 
 
Page 72 of 137 
 
10. 
BYRD ANTI-LOBBYING AMENDMENT 
 
a.
Standard. Each tier certifies to the tier above that it will not and has not used Federal 
appropriated funds to pay any person or organization for influencing or attempting to 
influence an officer or employee of any agency, a Member of Congress, officer or 
employee of Congress, or an employee of a Member of Congress in connection with 
obtaining any Federal contract, grant or any other award covered by 31 U.S.C. § 1352. 
FEMA’s regulation at 44 C.F.R. Part 18 implements the requirements of 31 U.S.C. § 
1352 and provides, in Appendix A to Part 18, a copy of the certification that is required 
to be completed by each entity as described in 31 U.S.C. § 1352. Each tier must also 
disclose any lobbying with non-Federal funds that takes place in connection with 
obtaining any Federal award. Such disclosures are forwarded from tier to tier up to the 
Federal awarding agency. 
b.
Applicability. This requirement applies to all FEMA grant and cooperative agreement 
programs. Contractors that apply or bid for a contract of $100,000 or more under a 
federal grant must file the required certification. See 2 C.F.R. Part 200, Appendix II(I); 
31 U.S.C. § 1352; and 44 C.F.R. Part18.
c. 
Suggested Language. 
Byrd Anti-Lobbying Amendment, 31 U.S.C. § 1352 (as amended) 
Contractors who apply or bid for an award of $100,000 or more shall file the required 
certification. Each tier certifies to the tier above that it will not and has not used Federal 
appropriated funds to pay any person or organization for influencing or attempting to 
influence an officer or employee of any agency, a Member of Congress, officer or 
employee of Congress, or an employee of a Member of Congress in connection with 
obtaining any Federal contract, grant, or any other award covered by 31 U.S.C. § 
1352. Each tier shall also disclose any lobbying with non-Federal funds that takes 
place in connection with obtaining any Federal award. Such disclosures are forwarded 
from tier to tier up to the recipient who in turn will forward the certification(s) to the 
awarding agency. 
 
d. 
Required Certification. If applicable, contractors must sign and submit to the non-federal 
entity the following certification. 
APPENDIX A, 44 C.F.R. PART 18 – CERTIFICATION REGARDING LOBBYING 
Certification for Contracts, Grants, Loans, and Cooperative Agreements
 
The undersigned certifies, to the best of his or her knowledge and belief, that: 
 
1. No Federal appropriated funds have been paid or will be paid, by or on behalf of 
the undersigned, to any person for influencing or attempting to influence an officer 
or employee of an agency, a Member of Congress, an officer or employee of 
Congress, or an employee of a Member of Congress in connection with the 
awarding of any Federal contract, the making of any Federal grant, the making of 
any Federal loan, the entering into of any cooperative agreement, and the 
extension, continuation, renewal, amendment, or modification of any Federal 
contract, grant, loan, or cooperative agreement.

Version June 28, 2023 
2024056 
 
 
 
 
Page 73 of 137 
2. If any funds other than Federal appropriated funds have been paid or will be paid 
to any person for influencing or attempting to influence an officer or employee of 
any agency, a Member of Congress, an officer or employee of Congress, or an 
employee of a Member of Congress in connection with this Federal contract, grant, 
loan, or cooperative agreement, the undersigned shall complete and submit 
Standard Form-LLL, “Disclosure Form to Report Lobbying,” in accordance with its 
instructions. 
3. The undersigned shall require that the language of this certification be included in 
the award documents for all subawards at all tiers (including subcontracts, 
subgrants, and contracts under grants, loans, and cooperative agreements) and 
that all subrecipients shall certify and disclose accordingly. 
 
This certification is a material representation of fact upon which reliance was placed 
when this transaction was made or entered into. Submission of this certification is a 
prerequisite for making or entering into this transaction imposed by section 1352, title 
31, U.S. Code. Any person who fails to file the required certification shall be subject to 
a civil penalty of not less than $10,000 and not more than $100,000 for each such 
failure. 
The Contractor,  
, certifies or affirms the truthfulness and 
accuracy of each statement of its certification and disclosure, if any. In addition, the 
Contractor understands and agrees that the provisions of 31 U.S.C. Chap. 38, 
Administrative Remedies for False Claims and Statements, apply to this certification 
and disclosure, if any. 
Signature of Contractor’s Authorized Official  
Name and Title of Contractor’s Authorized Official 
Date

2024056 
 
 
 
 
 
Page 74 of 137 
11. 
PROCUREMENT OF RECOVERED MATERIALS 
 
a. 
Standard. A non-Federal entity that is a state agency or agency of a political subdivision of a state 
and its contractors must comply with Section 6002 of the Solid Waste Disposal Act, as amended 
by the Resource Conservation and Recovery Act. See 2 C.F.R. Part 200, Appendix II(J); and 2 
C.F.R. § 200.322. 
b. 
Applicability. This requirement applies to all contracts awarded by a non- federal entity under 
FEMA grant and cooperative agreement programs. 
 
c. 
Requirements. The requirements of Section 6002 include procuring only items designated in 
guidelines of the EPA at 40 C.F.R. Part 247 that contain the highest percentage of recovered 
materials practicable, consistent with maintaining a satisfactory level of competition, where the 
purchase price of the item exceeds 
$10,000 or the value of the quantity acquired by the preceding fiscal year exceeded $10,000; 
procuring solid waste management services in a manner that maximizes energy and resource 
recovery; and establishing an affirmative procurement program for procurement of recovered 
materials identified in the EPA guidelines. 
 
d. 
Suggested Language. 
 
i. 
In the performance of this contract, the Contractor shall make maximum use of products 
containing recovered materials that are EPA-designated items unless the product cannot 
be acquired— 
1. 
Competitively within a timeframe providing for compliance with the contract 
performance schedule; 
2. 
Meeting contract performance requirements; or 
3. 
At a reasonable price. 
 
ii. 
Information about this requirement, along with the list of EPA- designated items, is 
available 
at 
EPA’s 
Comprehensive 
Procurement 
Guidelines 
web 
site, 
https://www.epa.gov/smm/comprehensive-procurement-guideline-cpg-program. 
 
iii. 
The Contractor also agrees to comply with all other applicable requirements of Section 
6002 of the Solid Waste Disposal Act.” 
 
12.       DOMESTIC PREFERENCES FOR PROCUREMENTS  
 
As appropriate, and to the extent consistent with law, CONTRACTOR should, to the greatest extent 
practicable under a federal award, provide a preference for the purchase, acquisition, or use of goods, 
products or materials produced in the United States. This includes, but is not limited to, iron, aluminum, 
steel, cement, and other manufactured products.  
 
Applicability For purchases in support of FEMA declarations and awards issued on or after November 12, 
2020, all FEMA recipients and subrecipients are required to include in all contracts and purchase orders for 
work or products a contract provision encouraging domestic preference for procurements.  
Domestic Preference for Procurements As appropriate, and to the extent consistent with law, the contractor 
should, to the greatest extent practicable, provide a preference for the purchase, acquisition, or use of 
goods, products, or materials produced in the United States. This includes, but is not limited to iron, 
aluminum, steel, cement, and other manufactured products. For purposes of this clause: Produced in the 
United States means, for iron and steel products, that all manufacturing processes, from the initial melting 
stage through the application of coatings, occurred in the United States. Manufactured products mean items 
and construction materials composed in whole or in part of non-ferrous metals such as aluminum; plastics 
and polymer-based products such as polyvinyl chloride pipe; aggregates such as concrete; glass, including 
optical fiber; and lumber.”

Version June 28, 2023 
2024056 
 
 
 
 
Page 75 of 137 
13.  ACCESS TO RECORDS 
 
a. Standard. All recipients, subrecipients, successors, transferees, and assignees must acknowledge 
and agree to comply with applicable provisions governing DHS access to records, accounts, 
documents, information, facilities, and staff. Recipients must give DHS/FEMA access to, and the 
right to examine and copy, records, accounts, and other documents and sources of information 
related to the federal financial assistance award and permit access to facilities, personnel, and 
other individuals and information as may be necessary, as required by DHS regulations and other 
applicable laws or program guidance. See DHS Standard Terms and Conditions: Version 8.1 
(2018). Additionally, Section 1225 of the Disaster Recovery Reform Act of 2018 prohibits FEMA 
from providing reimbursement to any state, local, tribal, or territorial government, or private non-
profit for activities made pursuant to a contract that purports to prohibit audits or internal reviews by 
the FEMA administrator or Comptroller General. 
 
Access to Records. The following access to records requirements apply to this contract:
i.The Contractor agrees to provide Participating Public Agency, the FEMA Administrator, the 
Comptroller General of the United States, or any of their authorized representatives access 
to any books, documents, papers, and records of the Contractor which are directly pertinent 
to this contract for the purposes of making audits, examinations, excerpts, and 
transcriptions. 
ii.The Contractor agrees to permit any of the foregoing parties to reproduce by any means 
whatsoever or to copy excerpts and transcriptions as reasonably needed. 
iii. The Contractor agrees to provide the FEMA Administrator or his authorized 
representatives access to construction or other work sites pertaining to the work being 
completed under the contract. 
 
iv.In compliance with the Disaster Recovery Act of 2018, the Participating Public Agency and 
the Contractor acknowledge and agree that no language in this contract is intended to 
prohibit audits or internal reviews by the FEMA Administrator or the Comptroller General of 
the United States. 
 
CHANGES 
 
a. Standard. To be eligible for FEMA assistance under the non-Federal entity’s FEMA grant or 
cooperative agreement, the cost of the change, modification, change order, or constructive change 
must be allowable, allocable, within the scope of its grant or cooperative agreement, and 
reasonable for the completion of project scope. 
 
b.
Applicability. FEMA recommends, therefore, that a non-Federal entity include a changes clause in 
its contract that describes how, if at all, changes can be made by either party to alter the method, 
price, or schedule of the work without breaching the contract. The language of the clause may differ 
depending on the nature of the contract and the end-item procured. 
 
15. DHS SEAL, LOGO, AND FLAGS 
 
a. Standard. Recipients must obtain permission prior to using the DHS seal(s), logos, crests, or 
reproductions of flags or likenesses of DHS agency officials. See DHS Standard Terms and 
Conditions: Version 8.1 (2018). 
 
b. Applicability. FEMA recommends that all non-Federal entities place in their contracts a provision 
that a contractor shall not use the DHS seal(s), logos, crests, or reproductions of flags or likenesses 
of DHS agency officials without specific FEMA pre-approval. 
 
c. “The contractor shall not use the DHS seal(s), logos, crests, or reproductions of flags or likenesses 
of DHS agency officials without specific FEMA pre-approval.

Version June 28, 2023 
2024056 
 
 
 
 
Page 76 of 137 
16. COMPLIANCE WITH FEDERAL LAW, REGULATIONS, AND EXECUTIVE ORDERS 
 
a.
Standard. The recipient and its contractors are required to comply withall Federal laws, regulations, 
and executive orders.
 
b. Applicability. FEMA recommends that all non-Federal entities place into their contracts an 
acknowledgement that FEMA financial assistance will be used to fund the contract along with the 
requirement that the contractor will comply with all applicable Federal law, regulations, executive 
orders, and FEMA policies, procedures, and directives. 
c. “This is an acknowledgement that FEMA financial assistance will be used to fund all or a portion of 
the contract. The contractor will comply with all applicable Federal law, regulations, executive 
orders, FEMA policies, procedures, and directives.” 
 
17. NO OBLIGATION BY FEDERAL GOVERNMENT 
 
a. Standard. FEMA is not a party to any transaction between the recipient and its contractor. FEMA is 
not subject to any obligations or liable to any party for any matter relating to the contract. 
 
b. Applicability. FEMA recommends that the non-Federal entity include a provision in its contract that 
states that the Federal Government is not a party to the contract and is not subject to any 
obligations or liabilities to the non-Federal entity, contractor, or any other party pertaining to any 
matter resulting from the contract. 
c. “The Federal Government is not a party to this contract and is not subject to any obligations or 
liabilities to the non-Federal entity, contractor, or any other party pertaining to any matter resulting 
from the contract.” 
 
18. PROGRAM FRAUD AND FALSE OR FRAUDULENT STATEMENTS OR RELATED ACTS 
 
a. Standard. Recipients must comply with the requirements of The False Claims Act (31 U.S.C. §§ 
3729-3733) which prohibits the submission of false or 
 fraudulent claims for payment to the federal government. See DHS Standard Terms and 
Conditions: Version 8.1 (2018); and 31 U.S.C. §§ 3801-3812, which details the administrative 
remedies for false claims and statements made. The non-Federal entity must include a provision 
in its contract that the contractor acknowledges that 31 U.S.C. Chap. 38 (Administrative 
Remedies for False Claims and Statements) applies to its actions pertaining to the contract. 
 
b. Applicability. FEMA recommends that the non-Federal entity include a provision in its contract that 
the contractor acknowledges that 31 U.S.C. Chap. 38 (Administrative Remedies for False Claims 
and Statements) applies to its actions pertaining to the contract. 
c. “The Contractor acknowledges that 31 U.S.C. Chap. 38 (Administrative Remedies for False Claims 
and Statements) applies to the Contractor’s actions pertaining to this contract.”  
 
d. In the event FTA or DOT funding is used by a Participating Public Agency, Contractor further 
acknowledges U.S. DOT regulations, “Program Fraud Civil Remedies,” 49 CFR Part 31, and apply 
to its actions pertaining to this Contract. Upon execution of the underlying Contract, Contractor 
certifies or affirms the truthfulness and accuracy of any statement it has made, it makes, it may 
make, or causes to me made, pertaining to the underlying Contract or the FTA assisted project for 
which this Contract Work is being performed. 
 
In addition to other penalties that may be applicable, Contractor further acknowledges that if it 
makes, or causes to be made, a false, fictitious, or fraudulent claim, statement, submission, or 
certification, the Federal Government reserves the right to impose the penalties of the Program 
Fraud Civil Remedies Act of 1986 on Contractor to the extent the Federal Government deems 
appropriate.

Version June 28, 2023 
2024056 
Page 77 of 137 
Contractor also acknowledges that if it makes, or causes to me made, a false, fictitious, or 
fraudulent claim, statement, submission, or certification to the Federal Government under a contract 
connected with a project that is financed in whole or in part with Federal assistance originally 
awarded by FTA under the authority of 49 U.S.C. § 5307, the Government reserves the right to 
impose the penalties of 18 U.S.C. § 1001 and 49 U.S.C. § 5307 (n)(1) on the Contractor, to the 
extent the Federal Government deems appropriate.  
Contractor agrees to include the above clauses in each subcontract financed in whole or in part 
with Federal assistance provided by FTA. It is further agreed that the clauses shall not be modified, 
except to identify the subcontractor who will be subject to the provisions. 
Offeror agrees to comply with all terms and conditions outlined in the FEMA Special Conditions section of 
this solicitation. 
Offeror’s Name: ______________________________________________ 
Address, City, State, and Zip Code: 
_____________________________________________________________________________ 
Phone Number: ________________________ Fax Number: ______________________________ 
Printed Name and Title of Authorized Representative: 
____________________________________________________________ 
Email Address: ___________ _________________________________ 
Signature of Authorized Representative: ____________________________________ 
Date: ________________________________

SCOPE OF WORK
This Scope of Work will be compiled into any resulting contract as Exhibit A. 
 
1. 
SCOPE OF WORK:  The City of Mesa (City) is issuing this Request for Proposal (RFP) to establish 
a contract for the purchase of Information Technology Solution Products and Services.  Details of 
the City’s objectives and requirements to which the RFP relates are set out in the scope of work, 
specifications, questionnaires, pricing document, etc. The City welcomes proposals that are 
responsive to this RFP (“Proposals”) respecting innovative or novel approaches to the City’s 
objectives and requirements.  
 
After implementation and acceptance of the proposed solution by the City, the initial term will be four 
(4) years with an opportunity to renew for up to an additional six (6) years.  The terms and conditions 
of any contract extension shall remain the same as the original contract as amended. 
 
Renewal options are based on Contractor(s) performance, service, and ability to provide high-
quality products and demonstrate cost containment efforts.  All renewal options and contract 
extensions shall be through a contract amendment and shall be at the sole discretion of the City. 
 
2. 
AWARD:  It is the City’s intention that a single or limited number of awards be made under this 
solicitation.  However, at the City’s sole discretion, the City may consider multiple awards. 
 
Should a current contract holder be selected and awarded a new contract, the City reserves the 
right to transition said contractor to the new contract.  The transition will take place over a three (3) 
to four (4) month period from the effective date of the newly awarded contract. 
 
3. 
CONFIDENTIALITY:  Unless receiving consent from the City Purchasing Office, Contractor shall 
not disclose, sell, or disseminate any data or information obtained in connection with this RFP and 
the resulting contract. 
 
4. 
MINIMUM QUALIFICATIONS:  The City has identified minimum qualifications for this Request for 
Proposal.  The minimum qualifications questions are located in Request for Proposal Questionnaire 
A.  Proposers are to read the requirements, and check yes or no.   
 
5. 
PRE-PROPOSAL CONFERENCE: 
a. Pre-Proposal Conference will be held via an online meeting. 
b. Pre-Proposal Conference – Date and Time:  November 30, 2023, at 9:00 A.M. Local 
Arizona Time  
i. To join the pre-proposal conference, please visit the following website:  
Microsoft Teams Meeting Invite. 
ii. Teleconference Number: 480-535-7460; Conference ID:  563 141 386# 
c. The purpose of this Pre-Proposal Conference is to provide an informal forum for Proposers 
to ask questions and gain clarifications on the requirements of the RFP.  All Proposers that 
require formal responses to their questions or clarification must submit their questions in 
writing to the Procurement Officer and Procurement Specialist referenced in the RFP.  All 
questions should be submitted via e-mail.  Please include the RFP number in all 
correspondence. 
d. Proposers are cautioned that all remarks, clarifications, or responses provided to questions 
during Pre-Proposal Conference are non-binding and must be submitted in writing via 
email. 
e. Deadline For Inquiries:  December 1, 2023 - 10:00 A.M. Local Arizona Time 
 
6. 
OMNIA PARTNERS CONTRACT REQUIREMENTS.  The City of Mesa, as the Principal 
Procurement Agency, defined in ATTACHMENT E, has partnered with OMNIA Partners, Public 
Sector (“OMNIA Partners”) to make the resultant contract (also known as the “Master Agreement” 
in materials distributed by OMNIA Partners) from this solicitation available to other public agencies 
nationally, including state and local governmental entities, public and private primary, secondary

SCOPE OF WORK
and higher education entities, non-profit entities, and agencies for the public benefit (“Public 
Agencies”), through OMNIA Partners’ cooperative purchasing program. The City of Mesa is acting 
as the contracting agency for any other Public Agency that elects to utilize the resulting Master 
Agreement.  Use of the Master Agreement by any Public Agency is preceded by their registration 
with OMNIA Partners (a “Participating Public Agency”) and by using the Master Agreement, any 
such Participating Public Agency agrees that it is registered with OMNIA Partners, whether 
pursuant to the terms of a Master Intergovernmental Cooperative Purchasing Agreement, a form 
of which is attached hereto on ATTACHMENT E, or as otherwise agreed to.  ATTACHMENT E 
contains additional information about OMNIA Partners and the cooperative purchasing program. 
  
OMNIA Partners is the largest and most experienced purchasing organization for public and private 
sector procurement.  Through the economies of scale created by OMNIA Partners’ public sector 
subsidiaries and affiliates, our participants have access to competitively solicited and publicly 
awarded cooperative agreements. For all public sector contracts, the lead agency contracting 
process continues to be the foundation on which we were established.  OMNIA Partners is proud 
to offer more value and resources to state and local government, higher education, K-12 education, 
and non-profits.   
 
OMNIA Partners provides shared services and supply chain optimization to government, education, 
and the private sector.  With corporate, pricing, and sales commitments from the Contractor, 
OMNIA Partners provides marketing and administrative support for the Contractor that directly 
promotes the Contractor’s products and services to Participating Public Agencies through multiple 
channels, each designed to promote specific products and services to Public Agencies on a 
national basis.  Participating Public Agencies benefit from pricing based on aggregate spend and 
the convenience of a contract that has already been advertised and publicly competed.  The 
Contractor benefits from a contract that generally allows Participating Public Agencies to directly 
purchase goods and services without the Contractor’s need to respond to additional competitive 
solicitations. As such, the Contractor must be able to accommodate a nationwide demand for 
services and to fulfill obligations as a nationwide Contractor, and respond to the OMNIA Partners 
documents (ATTACHMENT E).  
 
The City of Mesa anticipates spending approximately $150 million over the full potential Master 
Agreement term for Technology Solutions and Services.  While no minimum volume is guaranteed 
to the Supplier, the estimated annual volume of Technology Solutions and Services purchased 
under the Master Agreement through OMNIA Partners is approximately $1.5 billion.  This projection 
is based on the current annual volumes among the City of Mesa, other Participating Public 
Agencies anticipated to utilize the resulting Master Agreement to be made available to them 
through OMNIA Partners, and volume growth into other Public Agencies through a coordinated 
marketing approach between the Contractor and OMNIA Partners. 
 
7. 
ORDERING.  Although the City is open to alternate ordering methods, the primary methods for 
customers placing orders with the Supplier are the following: 
 
a. Online 
b. Email 
c. Telephone 
d. Fax 
 
8. 
DELIVERY REQUIREMENT.  The contractor agrees to deliver all products to the desktop of the 
ordering customer and be delivered F.O.B. destination, freight pre-paid and added, and allowed to 
various locations throughout the City.  The City of Mesa shall be responsible for extra fees incurred 
for expedited shipping or other special delivery requirements. Orders shipped to destinations in 
Alaska and Hawaii may incur additional freight fees. In many cases within the City, the Contractor 
may be asked to deliver all goods to the front counter within a given department.  This is the City 
of Mesa requirement and other participating agencies may have other delivery requirements.

SCOPE OF WORK
9. 
SCOPE OF PRODUCTS.  The intent of this solicitation is to establish a contract with the ability to 
purchase a comprehensive, wide variety of Information Technology Solution Products and Services 
including but not limited to the following categories:  
 
a. Software: 
 
National 
brand 
name 
Microsoft, 
Google, 
Oracle, 
Enterprise 
applications/solutions, cyber security applications/solutions, etc. 
 
b. Personal Computer Systems:  National brand name desktop PCs, notebooks, laptops, 
tablets, and other related devices from Enterprise Tier and Middle Tier Contractors that are 
business related computers, manufactured by companies, such as, Apple, COMPAQ, Dell, 
Gateway, Hewlett Packard, IBM / Lenovo, Panasonic, and Toshiba.  Product will include 
the operating system license, software media and documentation in the hardware 
shipment. 
 
c. Standard Business Workstation:  These will be used for typical tasks, which will include 
word processing, spreadsheet analysis, database management, business graphics, 
statistical analysis, internet, and other office automation activities.  Product will include the 
operating system license, software media and documentation in the hardware shipment. 
 
d. High End Workstation:  These will be used by application developers using GIS, CASE or 
other high-level language development tools, Computer Aided Design and Drafting 
professional, Internet Application developers or other sophisticated application work.  
Product will include the operating system license, software media and documentation in 
the hardware shipment. 
 
e. Laptop Computer or Notebook:  These will be used by traveling or remote access user for 
typical office automation and business productivity use.  With a port replicator or docking 
station, it may also be used as a standard desktop.  Product will include the operating 
system license, software media and documentation in the hardware shipment. 
 
f. 
Network Equipment:  This includes equipment primarily used for communications over an 
IP network.   This includes servers (physical and virtual), layer 2 and layer 3 switches, 
routers, area wireless access points, point-to-point wireless access, optics, media 
interfaces (i.e. serial, T1, T3, OC3) and fiber channel.  Class of equipment should include 
home office, small and medium business, and enterprise.  Contractors may include, but 
not limited to, Cisco Systems, Dell, Juniper Networks, HP, Extreme Networks, Enterasys 
Networks, D-Link, Netgear, and Brocade Communications Systems.   
 
g. Monitors:  These will include plug and play compatible monitors that are manufactured for 
the above systems and/or any other brand that may be specifically called for by the ordering 
entity and which meet the most current UL and OSHA requirements. 
 
h. Computer and Network Products, Peripherals, Accessories, and Components:  Complete 
availability of major manufacturer's product lines on items such as, but not limited to RAM, 
graphic accelerator cards, network interface cards, cables, printers, scanners, monitors, 
AV equipment, unified communications hardware, mobility hardware, modems, routers, 
switches, keyboards, drives, memory cards, cables, batteries, power management, 
supplies, etc. 
 
i. 
Information Technology/Educational Furniture:  Includes furniture design, delivery, 
installation, parts, maintenance, and repair and replacement. 
 
j. 
Services:  Services such as, but not limited to cloud computing, consulting, technical 
support, 
leasing/financing, 
trade-ins, 
repair, 
design, 
analysis, 
configuration, 
implementation, installation, training, maintenance, advisory, managed and support 
services, staff augmentation, professional services, etc.  In addition, services that are

SCOPE OF WORK
related to the design, use, or operation of the products being purchased such as system 
configurations, testing, hardware/software installation, upgrades, imaging, etc.  Services 
may also include materials, equipment, and supplies provided by the Reseller under an 
SOW. 
 
Note:  All hardware should come assembled.  For example, if extra memory, additional 
drives, or peripherals are ordered, the Contractor must install them unless the Participating 
Agency requests, that they not be installed.  
 
k. Comprehensive Product Offering: Offeror’s complete catalog and services offered shall be 
available.  Each offeror awarded a contract under this solicitation may offer their complete 
product and service offering. Pricing for products and services must be entered on the 
appropriate section of the Price Page. The City reserves the right to accept or reject any 
or all items offered. 
l. 
Financing: Options available such as lease programs and conditional sales contracts.   
10. LICENSES. Participating Agencies may be required to sign a separate agreement, rider, or End 
User Licensing Agreement (“EULA”), etc., as required by manufacturers. 
 
11. DEFECTIVE PRODUCT. All defective products shall be replaced and exchanged by the Contractor 
as permitted under the manufacturers’ return policy and Contractor’s Return Policy found at 
www.shi.com/returnpolicy. In any event, the original manufacturer or publisher’s policies (which 
may include processing as a warranty claim) will apply. Contractor will order a resplacement unit 
within one (1) business day of notice of damage, defect or DOA from the City. 
31. 
INTERVIEWS/DEMONSTRATION: 
 
The 
top 
scoring 
firm(s) 
may 
be 
invited 
for 
interviews/demonstrations at no additional cost to the City.  Proposers that refuse an invitation will 
be removed from further consideration in the RFP evaluation process. 
 
33. 
REQUIREMENTS:  The requirements stated in this Request for Proposal (Scope, Specifications, 
Questionnaires, pricing, etc. (collectively, the “Requirements”) are current as of the date issued, 
but they may change or be refined in the course of the evaluation of Proposals or otherwise. 
 
34. 
SUPPLEMENTAL PRODUCTS AND SERVICES:  The scope described in this RFP is preliminary 
in nature and intended to provide Proposers with a general overview of the major tasks envisioned 
as part of this solicitation.  The City reserves the right to expand and/or reduce the Project 
Objectives as may be appropriate based on the technical content of the successful Proposer’s 
proposal and/or during contract negotiations based on budget considerations. 
 
35. 
INVOICING/PAYMENT:   
 
a. Invoices shall be emailed to: 
i. Department of Innovation and Technology: DoITpayables@MesaAZ.gov for the 
fastest processing. 
ii. Vendors shall not invoice for products/service items not shipped or performed, as 
this will delay payment of the entire invoice. 
b. Invoices shall include the following: 
i. delivery order (DO) #, 
ii. part number(s), 
iii. products/services descriptions, 
iv. list price, percent discount, 
v. city cost (contract pricing), 
vi. if applicable sales tax.  
c. Contractor shall not invoice for items not delivered as this will delay payment of the entire 
invoice.

SCOPE OF WORK
d. Contractor shall e-mail invoices to the appropriate email address above no later than five 
(5) to seven (7) calendar days after the product/services is received by the City. 
e. Payment in full shall be made to the Contractor within thirty (30) days after receipt and 
approval of an invoice, unless terms other than net thirty (30) days are offered as a 
discount, at the City’s sole discretion. 
 
36. 
CONTRACT KICK-OFF MEETING:  A kick-off meeting will be held after the award of contract.  The 
contractor(s) and its team will meet with City of Mesa staff to conduct introductions and next steps. 
 
37. 
PROPOSAL QUESTIONNAIRES:   
 
a. Proposers shall use the Questionnaire/Response Forms provided.  (Attachment C) 
b. Proposal Questionnaire/Response Forms will be used to assist in determining which 
proposed solution is in the best interest of the City. 
c. The City is the sole judge as to determining what is in the best interest of the City. 
d. If supporting documentation is required, Proposer shall provide the documentation in the 
sequence set forth in the Request for Proposal and ensure all technical literature and/or 
narrative explanations fully address the specifics of the question.  Vague or disorganized 
responses that do not allow sufficient information for evaluation purposes may result in 
the rejection of a Proposal. 
e. Supporting documentation must be placed in TAB D. 
 
38. 
REQUEST FOR PROPOSAL PRICE SHEET:   
a. Proposals shall be submitted on the Pricing Form provided.   
b. Complete Price Sheet (Attachment A). 
i. The cost portion of the Response should include the following criteria: 
 
1. Provide price proposal as requested on the Pricing Document (Attachment 
A – “National” TAB) attached herein.  In addition to indicating your 
proposed discounts on the Price Page, you must also apply those 
discounts to the sample items listed in the City’s Market Basket listed in 
Attachment A.  
2. Propose and provide details of additional discounts or rebates for volume 
orders, special manufacturers’ offers, free goods program, total annual 
spend, etc. 
c. Price Proposal must be submitted using only the City’s Pricing Forms and in an MS Excel 
format. 
d. Failure to do so may result in the loss of points. 
e. The City of Mesa will not pay any hidden costs or add-on fees for equipment and services 
not described in the Proposer’s response. 
 
39. 
CONTRACT TERMS AND NEGOTIATION SCHEDULE:  Proposer will be expected to utilize the 
Agreements included in this Solicitation.  The Proposer will be expected to complete negotiation 
for the final contract within one (1) month from notice of intent to award of the contract and start 
working on the project within thirty (30) days after contract award or contract has been signed.  If 
an acceptable contract cannot be negotiated within this time frame, the City may formally end 
negotiations and begin negotiating with the next highest scoring Proposer.  
 
Awarded Contractor(s) will be required the sign the City of Mesa and OMNIA Partners agreements 
contained in this Request for Proposal.

Version June 28, 2023 
2024056 
 
 
 
 
Page 6 of 74 
Exhibit A  
Response for National Cooperative Contract 
1.0 
Scope of National Cooperative Contract 
 
Capitalized terms not otherwise defined herein shall have the meanings given to them 
in the Master Agreement or in the Administration Agreement between Supplier and 
OMNIA Partners. 
 
1.1 
Requirement 
 
The City of Mesa (hereinafter defined and referred to as “Principal 
Procurement Agency”), on behalf of itself and the National Intergovernmental 
Purchasing Alliance Company, a Delaware corporation d/b/a OMNIA Partners, 
Public Sector (“OMNIA Partners”), is requesting proposals for Technology 
Solutions and Services. The intent of this Request for Proposal is any contract 
between Principal Procurement Agency and Supplier resulting from this 
Request for Proposal (“Master Agreement”) be made available to other public 
agencies nationally, including state and local governmental entities, public and 
private primary, secondary and higher education entities, non-profit entities, 
and agencies for the public benefit (“Public Agencies”), through OMNIA 
Partners’ cooperative purchasing program.  The Principal Procurement 
Agency has executed a Principal Procurement Agency Certificate with OMNIA 
Partners, an example of which is included as Exhibit D, and has agreed to 
pursue the Master Agreement.  Use of the Master Agreement by any Public 
Agency is preceded by their registration with OMNIA Partners as a 
Participating Public Agency in OMNIA Partners’ cooperative purchasing 
program.  Registration with OMNIA Partners as a Participating Public Agency 
is accomplished by Public Agencies entering into a Master Intergovernmental 
Cooperative Purchasing Agreement, an example of which is attached as 
Exhibit C, and by using the Master Agreement, any such Participating Public 
Agency agrees that it is registered with OMNIA Partners, whether pursuant to 
the terms of the Master Intergovernmental Purchasing Cooperative Agreement 
or as otherwise agreed to.  The terms and pricing established in the resulting 
Master Agreement between the Supplier and the Principal Procurement 
Agency will be the same as that available to Participating Public Agencies 
through OMNIA Partners.   
 
All transactions, purchase orders, invoices, payments etc., will occur directly 
between the Supplier and each Participating Public Agency individually, and 
neither OMNIA Partners, any Principal Procurement Agency nor any 
Participating Public Agency, including their respective agents, directors, 
employees or representatives, shall be liable to Supplier for any acts, liabilities, 
damages, etc., incurred by any other Participating Public Agency. Supplier is 
responsible for knowing the tax laws in each state. 
 
This Exhibit A defines the expectations for qualifying Suppliers based on 
OMNIA Partners’ requirements to market the resulting Master Agreement 
nationally to Public Agencies.  Each section in this Exhibit A refers to the

Version June 28, 2023 
2024056 
 
 
 
 
Page 7 of 74 
capabilities, requirements, obligations, and prohibitions of competing 
Suppliers on a national level in order to serve Participating Public Agencies 
through OMNIA Partners.
 
These requirements are incorporated into and are considered an integral part 
of this RFP.  OMNIA Partners reserves the right to determine whether to make 
the Master Agreement awarded by the Principal Procurement Agency 
available to Participating Public Agencies, in its sole and absolute discretion, 
and any party submitting a response to this RFP acknowledges that any award 
by the Principal Procurement Agency does not obligate OMNIA Partners to 
make the Master Agreement available to Participating Procurement Agencies. 
 
1.2 
Marketing, Sales and Administrative Support 
 
During the term of the Master Agreement OMNIA Partners intends to provide 
marketing, sales, partnership development and administrative support for 
Supplier pursuant to this section that directly promotes the Supplier’s products 
and services to Participating Public Agencies through multiple channels, each 
designed to promote specific products and services to Public Agencies on a 
national basis. 
 
OMNIA Partners will assign the Supplier a Director of Partner Development 
who will serve as the main point of contact for the Supplier and will be 
responsible for managing the overall relationship between the Supplier and 
OMNIA Partners.  The Director of Partner Development will work with the 
Supplier to develop a comprehensive strategy to promote the Master 
Agreement and will connect the Supplier with appropriate stakeholders within 
OMNIA Partners including, Sales, Marketing, Contracting, Training, and 
Operations & Support. 
 
The OMNIA Partners marketing team will work in conjunction with Supplier to 
promote the Master Agreement to both existing Participating Public Agencies 
and prospective Public Agencies through channels that may include: 
 
A. Marketing collateral (print, electronic, email, presentations) 
B. Website  
C. Trade shows/conferences/meetings 
D. Advertising 
E.  Social Media 
 
The OMNIA Partners sales teams will work in conjunction with Supplier to 
promote the Master Agreement to both existing Participating Public Agencies 
and prospective Public Agencies through initiatives that may include: 
 
A. Individual sales calls  
B. Joint sales calls 
C. Communications/customer service

Version June 28, 2023 
2024056 
 
 
 
 
Page 8 of 74 
D. Training sessions for Public Agency teams
E. Training sessions for Supplier teams
The OMNIA Partners contracting teams will work in conjunction with Supplier 
to promote the Master Agreement to both existing Participating Public 
Agencies and prospective Public Agencies through:
A. Serving as the subject matter expert for questions regarding joint powers 
authority and state statutes and regulations for cooperative purchasing 
B. Training sessions for Public Agency teams
C. Training sessions for Supplier teams 
D. Regular business reviews to monitor program success
E. General contract administration 
Suppliers are required to pay an Administrative Fee of 1% of the greater of the 
Contract Sales under the Master Agreement and Guaranteed Contract Sales 
under this Request for Proposal.  Supplier will be required to execute the 
OMNIA Partners Administration Agreement (Exhibit B). At Supplier’s option, 
Suppliers may pay additional fees beyond administrative fees, such as 
technology fees, to OMNIA Partners and/or a third party for additional support 
and/or access to OMNIA Partners’ technology platform. 
 
1.3 
Estimated Volume 
 
The dollar volume purchased under the Master Agreement is estimated to be 
approximately 1.5 billion annually.  While no minimum volume is guaranteed 
to Supplier, the estimated annual volume is projected based on the current 
annual volumes among the Principal Procurement Agency, other Participating 
Public Agencies that are anticipated to utilize the resulting Master Agreement 
to be made available to them through OMNIA Partners, and volume growth 
into other Public Agencies through a coordinated marketing approach between 
Supplier and OMNIA Partners.   
 
1.4 
Award Basis 
 
The basis of any contract award resulting from this RFP made by Principal 
Procurement Agency will, at OMNIA Partners’ option, be the basis of award on 
a national level through OMNIA Partners.  If multiple Suppliers are awarded 
by Principal Procurement Agency under the Master Agreement, those same 
Suppliers will be required to extend the Master Agreement to Participating 
Public Agencies through OMNIA Partners.  Utilization of the Master Agreement 
by Participating Public Agencies will be at the discretion of the individual 
Participating Public Agency. Certain terms of the Master Agreement 
specifically applicable to the Principal Procurement Agency (e.g., governing 
law) are subject to modification for each Participating Public Agency as 
Supplier and such Participating Public Agency may agree without being in

Version June 28, 2023 
2024056 
 
 
 
 
Page 9 of 74 
conflict with the Master Agreement as a condition of the Participating Agency’s 
purchase and not a modification of the Master Agreement applicable to all 
Participating Agencies.  Participating Agencies may request to enter into a 
separate supplemental agreement to further define the level of service 
requirements over and above the minimum defined in the Master Agreement 
(e.g., governing law, invoice requirements, order requirements, specialized 
delivery, diversity requirements such as minority and woman owned 
businesses, 
historically 
underutilized 
business, 
etc.) 
(“Supplemental 
Agreement”).  It shall be the responsibility of the Supplier to comply, when 
applicable, with the prevailing wage legislation in effect in the jurisdiction of the 
Participating Agency.  It shall further be the responsibility of the Supplier to 
monitor the prevailing wage rates as established by the appropriate 
department of labor for any increase in rates during the term of the Master 
Agreement and adjust wage rates accordingly.  In instances where 
supplemental terms and conditions create additional risk and cost for Supplier, 
Supplier and Participating Public Agency may negotiate additional pricing 
above and beyond the stated contract not-to-exceed pricing so long as the 
added price is commensurate with the additional cost incurred by the Supplier. 
Any supplemental agreement developed as a result of the Master Agreement 
is exclusively between the Participating Agency and the Supplier (Contract 
Sales are reported to OMNIA Partners).   
 
All signed Supplemental Agreements and purchase orders issued and 
accepted by the Supplier may survive expiration or termination of the Master 
Agreement. Participating Agencies’ purchase orders may exceed the term of 
the Master Agreement if the purchase order is issued prior to the expiration of 
the Master Agreement.  Supplier is responsible for reporting all sales and 
paying the applicable Administrative Fee for sales that use the Master 
Agreement as the basis for the purchase order, even though Master 
Agreement may have expired. 
1.5 
Objectives of Cooperative Program  
 
This RFP is intended to achieve the following objectives regarding availability 
through OMNIA Partners’ cooperative program:  
A. Provide a comprehensive competitively solicited and awarded national 
agreement offering the Products covered by this solicitation to Participating 
Public Agencies;
B. Establish the Master Agreement as the Supplier’s primary go to market 
strategy to Public Agencies nationwide; 
C. Achieve cost savings for Supplier and Public Agencies through a single 
solicitation process that will reduce the Supplier’s need to respond to 
multiple solicitations and Public Agencies need to conduct their own 
solicitation process; 
D. Combine the aggregate purchasing volumes of Participating Public 
Agencies to achieve cost effective pricing.

Version June 28, 2023 
2024056 
 
 
 
 
Page 10 of 74 
2.0
REPRESENTATIONS AND COVENANTS
As a condition to Supplier entering into the Master Agreement, which would be 
available to all Public Agencies, Supplier must make certain representations, 
warranties and covenants to both the Principal Procurement Agency and OMNIA 
Partners designed to ensure the success of the Master Agreement for all 
Participating Public Agencies as well as the Supplier. 
 
2.1 
Corporate Commitment 
 
Supplier commits that (1) the Master Agreement has received all necessary 
corporate authorizations and support of the Supplier’s executive management, 
(2) the Master Agreement is Supplier's primary “go to market” strategy for 
Public Agencies, (3) the Master Agreement will be promoted to all Public 
Agencies, including any existing customers, and Supplier will transition 
existing customers, upon their request, to the Master Agreement, and (4) that 
the Supplier has read and agrees to the terms and conditions of the 
Administration Agreement with OMNIA Partners and will execute such 
agreement concurrent with and as a condition of its execution of the Master 
Agreement with the Principal Procurement Agency. Supplier will identify an 
executive corporate sponsor and a separate national account manager within 
the RFP response that will be responsible for the overall management of the 
Master Agreement. 
 
2.2 
RESERVED 
 
 Supplier commits to providing competitive pricing to Participating Public 
Agencies nationwide. If a Participating Public Agency is eligible for lower 
pricing through a national, state, regional, or local or cooperative contract, the 
Supplier will work with that Participating Public Agency accordiningly. 
2.3 
Sales Commitment 
Supplier commits to aggressively market the Master Agreement as its go to 
market strategy in this defined sector and that its sales force will be trained, 
engaged and committed to offering the Master Agreement to Public Agencies 
through OMNIA Partners nationwide. Supplier commits that all Master 
Agreement sales will be accurately and timely reported to OMNIA Partners in 
accordance with the OMNIA Partners Administration Agreement.  Supplier 
also commits its sales force will be compensated, including sales incentives, 
for sales to Public Agencies under the Master Agreement in a consistent or 
better manner compared to sales to Public Agencies if the Supplier were not 
awarded the Master Agreement.

Version June 28, 2023 
2024056 
 
 
 
 
Page 11 of 74 
3.0
SUPPLIER RESPONSE
Supplier must supply the following information for the Principal Procurement Agency 
to determine Supplier’s qualifications to extend the resulting Master Agreement to 
Participating Public Agencies through OMNIA Partners.   
 
3.1 
Company 
 
A. Brief history and description of Supplier to include experience providing 
similar products and services. 
B. Total number and location of salespersons employed by Supplier. 
C. Number and location of support centers (if applicable) and location of 
corporate office. 
D. Annual sales for the three previous fiscal years. 
a. Submit FEIN and Dunn & Bradstreet report. 
E. Describe any green or environmental initiatives or policies. 
F. Describe any diversity programs or partners supplier does business with 
and how Participating Agencies may use diverse partners through the 
Master Agreement.  Indicate how, if at all, pricing changes when using the 
diversity program. If there are any diversity programs, provide a list of 
diversity alliances and a copy of their certifications. 
G. Indicate if supplier holds any of the below certifications in any classified 
areas and include proof of such certification in the response: 
a. Minority Women Business Enterprise 
Yes 
 No 
If yes, list certifying agency: ______________________________ 
b.  Small Business Enterprise (SBE) or Disadvantaged Business 
Enterprise (DBE)  
Yes 
 No 
If yes, list certifying agency: ______________________________ 
c. Historically Underutilized Business (HUB)
Yes 
 No 
If yes, list certifying agency: ______________________________ 
d. Historically Underutilized Business Zone Enterprise (HUBZone)
Yes 
 No 
If yes, list certifying agency: ______________________________ 
e. Other recognized diversity certificate holder 
Yes 
 No 
 
If yes, list certifying agency: ______________________________ 
H. 
List any relationships with subcontractors or affiliates intended to be used 
when providing services and identify if subcontractors meet minority-

Version June 28, 2023 
2024056 
 
 
 
 
Page 12 of 74 
owned standards. If any, list which certifications subcontractors hold and 
certifying agency. 
I.
Describe how supplier differentiates itself from its competitors.
 
J. Describe any present or past litigation, bankruptcy or reorganization 
involving supplier.  
K. Felony Conviction Notice: Indicate if the supplier 
a. is a publicly held corporation and this reporting requirement is not 
applicable;
b. is not owned or operated by anyone who has been convicted of a 
felony; or 
c. is owned or operated by and individual(s) who has been convicted 
of a felony and provide the names and convictions. 
L. Describe any debarment or suspension actions taken against supplier
 
3.2 
Distribution, Logistics 
 
A. Each offeror awarded an item under this solicitation may offer their 
complete product and service offering/a balance of line. Describe the full 
line of products and services offered by supplier.
 
B. Describe how supplier proposes to distribute the products/service 
nationwide. Include any states where products and services will not be 
offered under the Master Agreement, including U.S. Territories and 
Outlying Areas. 
 
C. Describe how Participating Agencies are ensured they will receive the 
Master Agreement pricing; include all distribution channels such as direct 
ordering, retail or in-store locations, through distributors, etc. Describe 
how Participating Agencies verify and audit pricing to ensure its 
compliance with the Master Agreement. 
 
D. Identify all other companies that will be involved in processing, handling 
or shipping the products/service to the end user. 
 
E. Provide the number, size and location of Supplier’s distribution facilities, 
warehouses and retail network as applicable. 
 
3.3 Marketing and Sales 
A. Provide a detailed ninety-day plan beginning from award date of the Master 
Agreement describing the strategy to immediately implement the Master 
Agreement as supplier’s primary go to market strategy for Public Agencies 
to supplier’s teams nationwide, to include, but not limited to: 
 
i. 
Executive leadership endorsement and sponsorship of the award as 
the public sector go-to-market strategy within first 10 days

Version June 28, 2023 
2024056 
 
 
 
 
Page 13 of 74 
ii.
Training and education of Supplier’s national sales force with 
participation from the Supplier’s executive leadership, along with the 
OMNIA Partners team within first 90 days
 
B. Provide a detailed ninety-day plan beginning from award date of the Master 
Agreement describing the strategy to market the Master Agreement to 
current Participating Public Agencies, existing Public Agency customers of 
Supplier, as well as to prospective Public Agencies nationwide immediately 
upon award, to include, but not limited to: 
i.
Creation and distribution of a co-branded press release to trade 
publications
ii.
Announcement, Master Agreement details and contact information 
published on the Supplier’s website within first 90 days 
iii. 
Design, publication and distribution of co-branded marketing 
materials within first 90 days
iv. 
Commitment to attendance and participation with OMNIA Partners 
at national (i.e. NIGP Annual Forum, NPI Conference, etc.), regional 
(i.e. Regional NIGP Chapter Meetings, Regional Cooperative 
Summits, etc.) and supplier-specific trade shows, conferences and
meetings throughout the term of the Master Agreement 
v. 
Commitment to attend, exhibit and participate at the NIGP Annual 
Forum in an area reserved by OMNIA Partners for partner suppliers.  
Booth space will be purchased and staffed by Supplier.  In addition, 
Supplier commits to provide reasonable assistance to the overall 
promotion and marketing efforts for the NIGP Annual Forum, as 
directed by OMNIA Partners. 
vi. 
Design and publication of national and regional advertising in trade 
publications throughout the term of the Master Agreement 
vii. 
Ongoing marketing and promotion of the Master Agreement 
throughout its term (case studies, collateral pieces, presentations, 
promotions, etc.) 
viii. 
Dedicated OMNIA Partners internet web-based homepage on 
Supplier’s website with: 
 OMNIA Partners standard logo; 
 Copy of original Request for Proposal; 
 Copy of Master Agreement and amendments between 
Principal Procurement Agency and Supplier; 
 Summary of Products and pricing; 
 Marketing Materials 
 Electronic link to OMNIA Partners’ website including the 
online registration page;

Version June 28, 2023 
2024056 
 
 
 
 
Page 14 of 74 
 A dedicated toll-free number and email address for OMNIA 
Partners 
C. Describe how Supplier will transition any existing Public Agency customers’ 
accounts to the Master Agreement available nationally through OMNIA 
Partners. Include a list of current cooperative contracts (regional and 
national) Supplier holds and describe how the Master Agreement will be 
positioned among the other cooperative agreements. 
 
D. Acknowledge Supplier agrees to provide its logo(s) to OMNIA Partners and 
agrees to provide permission for reproduction of such logo in marketing 
communications and promotions.  Acknowledge that use of OMNIA 
Partners logo will require permission for reproduction, as well. 
 
E. Confirm Supplier will be proactive in direct sales of Supplier’s goods and 
services to Public Agencies nationwide and the timely follow up to leads 
established by OMNIA Partners. All sales materials are to use the OMNIA 
Partners logo. At a minimum, the Supplier’s sales initiatives should 
communicate: 
 
i. 
Master Agreement was competitively solicited and publicly awarded 
by a Principal Procurement Agency 
ii. 
Best government pricing 
iii. 
No cost to participate 
iv. 
Non-exclusive  
 
F. Confirm Supplier will train its national sales force on the Master Agreement.  
At a minimum, sales training should include: 
 
i. 
Key features of Master Agreement 
ii. 
Working knowledge of the solicitation process 
iii. 
Awareness of the range of Public Agencies that can utilize the 
Master Agreement through OMNIA Partners
iv. 
Knowledge of benefits of the use of cooperative contracts
 
G. Provide the name, title, email and phone number for the person(s), who will 
be responsible for:  
 
i. 
Executive Support 
ii. 
Marketing 
iii. 
Sales 
iv. 
Sales Support 
v. 
Financial Reporting 
vi. 
Accounts Payable 
vii.
Contracts

Version June 28, 2023 
2024056 
 
 
 
 
Page 15 of 74 
H. Describe in detail how Supplier’s national sales force is structured, 
including contact information for the highest-level executive in charge of 
the sales team.
 
I.  Explain in detail how the sales teams will work with the OMNIA Partners 
team to implement, grow and service the national program. 
 
I. Explain in detail how Supplier will manage the overall national program 
throughout the term of the Master Agreement, including ongoing 
coordination of marketing and sales efforts, timely new Participating Public 
Agency account set-up, timely contract administration, etc. 
 
J. State the amount of Supplier’s Public Agency sales for the previous fiscal 
year.  Provide a list of Supplier’s top 10 Public Agency customers, the total 
purchases for each for the previous fiscal year along with a key contact for 
each. 
 
K. Describe Supplier’s information systems capabilities and limitations 
regarding order management through receipt of payment, including 
description of multiple platforms that may be used for any of these 
functions. 
 
L. Provide the Contract Sales (as defined in Section 12 of the OMNIA 
Partners Administration Agreement) that Supplier will guarantee each year 
under the Master Agreement for the initial three years of the Master 
Agreement (“Guaranteed Contract Sales”). 
 
$_______.00 in year one 
$_______.00 in year two 
$_______.00 in year three 
 
To the extent Supplier guarantees minimum Contract Sales, the 
Administrative Fee shall be calculated based on the greater of the 
actual Contract Sales and the Guaranteed Contract Sales. 
 
M. Even though it is anticipated many Public Agencies will be able to utilize 
the Master Agreement without further formal solicitation, there may be 
circumstances where Public Agencies will issue their own solicitations. The 
following options are available when responding to a solicitation for 
Products covered under the Master Agreement.  
 
i. 
Respond with Master Agreement pricing (Contract Sales 
reported to OMNIA Partners). 
ii. 
If competitive conditions require pricing lower than the 
standard Master Agreement not-to-exceed pricing, Supplier 
may respond with lower pricing through the Master Agreement. 
If Supplier is awarded the contract, the sales are reported as 
Contract Sales to OMNIA Partners under the Master 
Agreement.

Version June 28, 2023 
2024056 
 
 
 
 
Page 16 of 74 
iii.
Respond with pricing higher than Master Agreement only in the 
unlikely event that the Public Agency refuses to utilize Master 
Agreement (Contract Sales are not reported to OMNIA 
Partners).
iv.
If alternative or multiple proposals are permitted, respond with 
pricing higher than Master Agreement, and include Master 
Agreement as the alternate or additional proposal. 
 
Detail Supplier’s strategies under these options when responding to a 
solicitation.

Version June 28, 2023 
2024056 
 
 
 
 
Page 17 of 74 
Exhibit B 
Administration Agreement, Example 
ADMINISTRATION AGREEMENT 
THIS ADMINISTRATION AGREEMENT (this “Agreement”) is made this ___ day of 
______ 20__, between National Intergovernmental Purchasing Alliance Company, a 
Delaware corporation d/b/a OMNIA Partners, Public Sector (“OMNIA Partners”), and 
________________ (“Supplier”). 
RECITALS
 
 
WHEREAS, the ___________________ (the “Principal Procurement Agency”) has 
entered into a Master Agreement effective _________________, Agreement No_______, 
by and between the Principal Procurement Agency and Supplier, (as may be amended from 
time to time in accordance with the terms thereof, the “Master Agreement”), as attached 
hereto as Exhibit A and incorporated herein by reference as though fully set forth herein, for 
the purchase of ____________________________ (the “Product”); 
WHEREAS, said Master Agreement provides that any or all public agencies, 
including state and local governmental entities, public and private primary, secondary and 
higher education entities, non-profit entities, and agencies for the public benefit (collectively, 
“Public Agencies”), that register (either via registration on the OMNIA Partners website or 
execution of a Master Intergovernmental Cooperative Purchasing Agreement, attached 
hereto as Exhibit B) (each, hereinafter referred to as a “Participating Public Agency”) may 
purchase Product at prices stated in the Master Agreement; 
 
 
WHEREAS, Participating Public Agencies may access the Master Agreement which 
is offered through OMNIA Partners to Public Agencies; 
 
 
WHEREAS, OMNIA Partners serves as the cooperative contract administrator of the 
Master Agreement on behalf of Principal Procurement Agency; 
 
 
WHEREAS, Principal Procurement Agency desires OMNIA Partners to proceed with 
administration of the Master Agreement; and 
 
 
WHEREAS, OMNIA Partners and Supplier desire to enter into this Agreement to 
make available the Master Agreement to Participating Public Agencies and to set forth 
certain terms and conditions governing the relationship between OMNIA Partners and 
Supplier. 
 
 
NOW, THEREFORE, in consideration of the payments to be made hereunder and 
the mutual covenants contained in this Agreement, OMNIA Partners and Supplier hereby 
agree as follows:

Version June 28, 2023 
2024056 
 
 
 
 
Page 18 of 74 
DEFINITIONS
1.
Capitalized terms used in this Agreement and not otherwise defined herein 
shall have the meanings given to them in the Master Agreement. 
 
 
TERMS AND CONDITIONS
 
 
2. 
The Master Agreement and the terms and conditions contained therein shall 
apply to this Agreement except as expressly changed or modified by this Agreement.  
Supplier acknowledges and agrees that the covenants and agreements of Supplier set forth 
in the solicitation and Supplier’s response thereto resulting in the Master Agreement are 
incorporated herein and are an integral part hereof. 
 
 
3. 
OMNIA Partners shall be afforded all of the rights, privileges and 
indemnifications afforded to Principal Procurement Agency by or from Supplier under the 
Master Agreement, and such rights, privileges and indemnifications shall accrue and apply 
with equal effect to OMNIA Partners, its agents, employees, directors, and representatives 
under this Agreement including, but not limited to, Supplier’s obligation to obtain appropriate 
insurance. 
 
 
4. 
OMNIA Partners shall perform all of its duties, responsibilities and obligations as the 
cooperative contract administrator of the Master Agreement on behalf of Principal Procurement 
Agency as set forth herein, and Supplier hereby acknowledges and agrees that all duties, 
responsibilities and obligations will be undertaken by OMNIA Partners solely in its capacity as the 
cooperative contract administrator under the Master Agreement. 
 
 
5. 
With respect to any purchases by Principal Procurement Agency or any 
Participating Public Agency pursuant to the Master Agreement, OMNIA Partners shall not 
be: (i) construed as a dealer, re-marketer, representative, partner or agent of any type of the 
Supplier, Principal Procurement Agency or any Participating Public Agency; (ii) obligated, 
liable or responsible for any order for Product made by Principal Procurement Agency or 
any Participating Public Agency or any employee thereof under the Master Agreement or for 
any payment required to be made with respect to such order for Product; and (iii) obligated, 
liable or responsible for any failure by Principal Procurement Agency or any Participating 
Public Agency to comply with procedures or requirements of applicable law or the Master 
Agreement or to obtain the due authorization and approval necessary to purchase under the 
Master Agreement. OMNIA Partners makes no representation or guaranty with respect to 
any minimum purchases by Principal Procurement Agency or any Participating Public 
Agency or any employee thereof under this Agreement or the Master Agreement. 
 
 
6. 
OMNIA Partners shall not be responsible for Supplier’s performance under the 
Master Agreement, and Supplier shall hold OMNIA Partners harmless from any liability that 
may arise from the negligent acts or omissions of Supplier in with the course of its 
performance under the Master Agreement. 
 
7. 
Supplier acknowledges that, in connection with its access to OMNIA Partners 
confidential information and/or supply of data to OMNIA Partners, it has complied with and 
shall continue to comply with all laws, regulations and standards that may apply to Supplier, 
including, without limitation: (a) United States federal and state information security and

Version June 28, 2023 
2024056 
 
 
 
 
Page 19 of 74 
privacy statutes, regulations and/or best practices, including, without limitation, the Gramm-
Leach-Bliley Act, the Massachusetts Data Security Regulations (201 C.M.R. 17.00 et. seq.), 
the Nevada encryption statute (N.R.S. § 603A), the California data security law (Cal. Civil 
Code § 1798.80 et. seq.) and California Consumer Privacy Act (Cal. Civil Code § 1798.100 
et. seq.); and (b) applicable industry and regulatory standards and best practices 
(collectively, “Data Regulations”).     
With regard to Personal Information that Supplier collects, receives, or otherwise 
processes under the Agreement or otherwise in connection with performance of the 
Agreement, Supplier agrees that it will not: (i) sell, rent, release, disclose, disseminate, make 
available, transfer, or otherwise communicate orally, in writing, or by electronic or other 
means, such Personal Information to another business or third party for monetary or other 
valuable consideration; or (ii) retain, use, or disclose such Personal Information outside of 
the direct business relationship between Supplier and OMNIA Partners or for any purpose 
other than for the specific purpose of performance of the Agreement, including retaining, 
using, or disclosing such Personal Information for a commercial purpose other than for 
performance of the Agreement. By entering into the Agreement, Supplier certifies that it 
understands the specific restrictions contained in this Section 7 and will comply with them.
For purposes hereof, “Personal Information” means information that identifies, relates to, 
describes, is reasonably capable of being associated with, or could reasonably be linked, 
directly or indirectly, with a particular consumer or household, and includes the specific 
elements of “personal information” as defined under Data Regulations, as defined herein.
Supplier will reasonably assist OMNIA Partners in timely responding to any third party
“request to know” or “request to delete” (as defined pursuant to Data Regulations) and will 
promptly provide OMNIA Partners with information reasonably necessary for OMNIA 
Partners to respond to such requests. Where Supplier collects Personal Information directly 
from Public Agencies or others on OMNIA Partners’ behalf, Supplier will maintain records 
and the means necessary to enable OMNIA Partners to respond to such requests to know 
and requests to delete. 
 
 
8. 
WITHOUT LIMITING THE GENERALITY OF THE FOREGOING, OMNIA 
PARTNERS EXPRESSLY DISCLAIMS ALL EXPRESS OR IMPLIED REPRESENTATIONS 
AND WARRANTIES REGARDING OMNIA PARTNERS’ PERFORMANCE AS A 
COOPERATIVE CONTRACT ADMINISTRATOR OF THE MASTER AGREEMENT. 
NEITHER PARTY SHALL NOT BE LIABLE IN ANY WAY FOR ANY SPECIAL, 
INCIDENTAL, INDIRECT, CONSEQUENTIAL, EXEMPLARY, PUNITIVE, OR RELIANCE 
DAMAGES, INCLUDING, BUT NOT LIMITED TO, LOSS OF OR DAMAGE TO DATA, LOSS 
OF ANTICIPAGED REVENUE OR PROFITS, WORK STOPPAGE OR IMPAIRMENT OF 
OTHER ASSETS, WHETHER OR NOT FORESEEABLE, EVEN IF A PARTY IS ADVISED 
OF THE POSSIBILITY OF SUCH DAMAGES.  
 
EXCEPT AS OTHERWISE PROVIDED IN THIS AGREEMENT AND/OR ANY ORDER 
ISSUED HEREUNDER, SUPPLIER HEREBY DISCLAIMS ALL OTHER WARRANTIES, 
EITHER EXPRESS OR IMPLIED, INCLUDING, BUT NOT LIMITED TO ANY WARRANTY 
OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, WARRANTY OF 
NONINFRINGEMENT, OR ANY WARRANTY RELATED TO THIRD PARTY SERVICES OR 
PRODUCTS. THIS DISCLAIMER DOES NOT AFFECT THE TERMS OF ANY WARRANTY 
PROVIDED BY AN ORIGINAL MANUFACTURER OR PUBLISHER. 
 
TERM OF AGREEMENT; TERMINATION

Version June 28, 2023 
2024056 
 
 
 
 
Page 20 of 74 
9.
This Agreement shall be in effect so long as the Master Agreement remains in 
effect, provided, however, that the provisions of Sections 3 – 8 and 11 – 22, hereof and the 
indemnifications limitations of liability afforded by the Supplier to OMNIA Partners in the 
Master Agreement, to the extent such provisions survive any expiration or termination of the 
Master Agreement, shall survive the expiration or termination of this Agreement. 
 
NATIONAL PROMOTION 
 
 
10. 
OMNIA Partners and Supplier shall publicize and promote the availability of 
the Master Agreement’s products and services to Public Agencies and such agencies’ 
employees. Supplier shall require each Public Agency to register its participation in the 
OMNIA Partners program by either registering on the OMNIA Partners website 
(www.omniapartners.com/publicsector) 
or 
executing 
a 
Master 
Intergovernmental 
Cooperative Purchasing Agreement prior to processing the Participating Public Agency’s 
first sales order.  Upon request, Supplier shall make available to interested Public Agencies 
a copy of the Master Agreement and such price lists or quotes as may be necessary for such 
Public Agencies to evaluate potential purchases. 
 
 
11. 
Supplier shall provide such marketing and administrative support as set forth 
in the solicitation resulting in the Master Agreement, including assisting in development of 
marketing materials as reasonably requested by Principal Procurement Agency and OMNIA 
Partners. Supplier shall be responsible for obtaining permission or license of use and 
payment of any license fees for all content and images Supplier provides to OMNIA Partners 
or posts on the OMNIA Partners website. Supplier shall indemnify, defend and hold harmless 
OMNIA Partners for use of all such content and images including copyright infringement 
claims. Supplier and OMNIA Partners each hereby grant to the other party a limited, 
revocable, non-transferable, non-sublicensable right to use such party’s logo (each, the 
“Logo”) solely for use in marketing the Master Agreement. Each party shall provide the other 
party with the standard terms of use of such party’s Logo, and such party shall comply with 
such terms in all material respects.  Both parties shall obtain approval from the other party 
prior to use of such party’s Logo.   Notwithstanding the foregoing, the parties understand 
and agree that except as provided herein neither party shall have any right, title or interest 
in the other party’s Logo.  Upon termination of this Agreement, each party shall immediately 
cease use of the other party’s Logo.
 
ADMINISTRATIVE FEE, REPORTING & PAYMENT 
 
 
12. 
An  “Administrative Fee” shall be defined and due to OMNIA Partners from Supplier
in the amount of __ percent (__%) (“Administrative Fee Percentage”) multiplied by the total 
purchase amount paid to Supplier, less refunds and credits on returns, for the sale of products and/or 
services to Principal Procurement Agency and Participating Public Agencies pursuant to the Master 
Agreement (as amended from time to time and including any renewal thereof) (“Contract Sales”).  
From time to time the parties may mutually agree in writing to a lower Administrative Fee Percentage 
for a specifically identified Participating Public Agency’s Contract Sales.   
 
 
13. 
Supplier shall provide OMNIA Partners with an electronic accounting report monthly, 
in the format prescribed by OMNIA Partners, summarizing all Contract Sales for each calendar 
month.  The Contract Sales reporting format is provided as Exhibit C (“Contract Sales Report”),
attached hereto and incorporated herein by reference. Contract Sales Reports for each calendar month

Version June 28, 2023 
2024056 
 
 
 
 
Page 21 of 74 
shall be provided by Supplier to OMNIA Partners by the 10th day of the following month.  Failure to 
provide a Contract Sales Report within the time and manner specified herein shall constitute a material 
breach of this Agreement and if not cured within thirty (30) days of written notice to Supplier shall 
be deemed a cause for termination of the Master Agreement, at Principal Procurement Agency’s sole 
discretion, and/or this Agreement, at OMNIA Partners’ sole discretion.
 
14. 
Administrative Fee payments are to be paid by Supplier to OMNIA Partners at the 
frequency and on the due date stated in Section 13, above, for Supplier’s submission of corresponding 
Contract Sales Reports. Administrative Fee payments are to be made via Automated Clearing House 
(ACH) to the OMNIA Partners designated financial institution identified in Exhibit D.   Failure to 
provide a payment of the Administrative Fee within the time and manner specified herein shall 
constitute a material breach of this Agreement and if not cured within thirty (30) days of written notice 
to Supplier shall be deemed a cause for termination of the Master Agreement, at Principal 
Procurement Agency’s sole discretion, and/or this Agreement, at OMNIA Partners’ sole discretion. 
All Administrative Fees not paid when due shall bear interest at a rate equal to the lesser of one and 
one-half percent (1 1/2%) per month or the maximum rate permitted by law until paid in full.
 
15.  
Supplier shall maintain an accounting of all purchases made by Participating Public 
Agencies under the Master Agreement.  OMNIA Partners, or its designee, in OMNIA Partners’ sole 
discretion, reserves the right to compare Participating Public Agency records with Contract Sales 
Reports submitted by Supplier for a period of four (4) years from the date OMNIA Partners receives 
such report.  In addition, OMNIA Partners may engage a third party to conduct an independent audit 
of Supplier’s monthly reports.  In the event of such an audit, Supplier shall provide all materials 
reasonably requested relating to such audit by OMNIA Partners at the location designated by OMNIA 
Partners. OMNIA Partners shall request to audit Supplier by providing at least thirty (30) days’ 
written notice to Suppler and such audits shall be limited to not more than once per calendar year. In 
the event an underreporting of Contract Sales and a resulting underpayment of Administrative Fees 
is revealed, OMNIA Partners will notify the Supplier in writing.  Supplier will have thirty (30) days 
from the date of such notice to resolve the discrepancy to OMNIA Partners’ reasonable satisfaction, 
including payment of any Administrative Fees due and owing, together with interest thereon in 
accordance with Section 13, and reimbursement of OMNIA Partners’ costs and expenses related to 
such audit. 
 
GENERAL PROVISIONS 
 
 
16. 
This Agreement, the Master Agreement and the exhibits referenced herein 
supersede any and all other agreements, either oral or in writing, between the parties hereto 
with respect to the subject matter hereto and no other agreement, statement, or promise 
relating to the subject matter of this Agreement which is not contained or incorporated herein 
shall be valid or binding.  In the event of any conflict between the provisions of this 
Agreement and the Master Agreement, as between OMNIA Partners and Supplier, the 
provisions of this Agreement shall prevail.   
 
 
17. 
If any action at law or in equity is brought to enforce or interpret the provisions 
of this Agreement or to recover any Administrative Fee and accrued interest, the prevailing 
party shall be entitled to reasonable attorney’s fees and costs in addition to any other relief 
to which it may be entitled. 
 
 
18. 
This Agreement and OMNIA Partners’ rights and obligations hereunder may 
be assigned at OMNIA Partners’ sole discretion to an affiliate of OMNIA Partners, any

Version June 28, 2023 
2024056 
 
 
 
 
Page 22 of 74 
purchaser of any or all or substantially all of the assets of OMNIA Partners, or the successor 
entity as a result of a merger, reorganization, consolidation, conversion or change of control, 
whether by operation of law or otherwise with Supplier’s written consent, which shall not be 
unreasonably withheld.  Supplier may not assign its obligations hereunder without the prior 
written consent of OMNIA Partners, which shall not be unreasonably withheld.
Notwithstanding the foregoing, either may assign this Agreement to a successor pursuant 
to a merger, consolidation, or sale of all or substantially all its assets. 
 
 
19. 
All written communications given hereunder shall be delivered by first-class 
mail, postage prepaid, or overnight delivery on receipt to the addresses as set forth below.  
 
A. OMNIA Partners: 
 
OMNIA Partners 
5001 Aspen Grove 
Franklin, TN 37067 
Attention: Legal Department - Public Sector Contracting 
 
B. Supplier: 
SHI International Corp. 
290 Davidson Ave
Somerset, NJ 08873 
____________________ 
 
 
20. 
If any provision of this Agreement shall be deemed to be, or shall in fact be, 
illegal, inoperative or unenforceable, the same shall not affect any other provision or 
provisions herein contained or render the same invalid, inoperative or unenforceable to any 
extent whatever, and this Agreement will be construed by limiting or invalidating such 
provision to the minimum extent necessary to make such provision valid, legal and 
enforceable. 
 
 
21. 
This Agreement may not be amended, changed, modified, or altered without 
the prior written consent of the parties hereto, and no provision of this Agreement may be 
discharged or waived, except by a writing signed by the parties.  A waiver of any particular 
provision will not be deemed a waiver of any other provision, nor will a waiver given on one 
occasion be deemed to apply to any other occasion.  
 
 
22. 
This Agreement shall inure to the benefit of and shall be binding upon OMNIA 
Partners, the Supplier and any respective successor and assign thereto; subject, however, 
to the limitations contained herein. 
 
 
23. 
This Agreement will be construed under and governed by the laws of the State 
of Delaware, excluding its conflicts of law provisions and any action arising out of or related 
to this Agreement shall be commenced solely and exclusively in the state or federal courts 
in Williamson County Tennessee. 
 
 
24. 
This Agreement may be executed in counterparts, each of which is an original 
but all of which, together, shall constitute but one and the same instrument. The exchange 
of copies of this Agreement and of signature pages by facsimile, or by .pdf or similar 
electronic transmission, will constitute effective execution and delivery of this Agreement as

Version June 28, 2023 
2024056 
 
 
 
 
Page 23 of 74 
to the parties and may be used in lieu of the original Agreement for all purposes. Signatures 
of the parties transmitted by facsimile, or by .pdf or similar electronic transmission, will be 
deemed to be their original signatures for any purpose whatsoever.
 
[INSERT SUPPLIER ENTITY NAME] 
 
NATIONAL 
INTERGOVERNMENTAL 
PURCHASING ALLIANCE 
COMPANY, A DELAWARE 
CORPORATION D/B/A OMNIA 
PARTNERS, PUBLIC SECTOR 
 
 
Signature
 
 
Signature 
Sarah Vavra 
Name 
 
 
Name 
Sr. Vice President, Public Sector 
Contracting 
Title 
 
 
Title 
Date 
 
Date

2024056 
 
 
 
 
 
Page 24 of 74
Exhibit C
Master Intergovernmental Cooperative Purchasing Agreement, Example
 
MASTER INTERGOVERNMENTAL COOPERATIVE PURCHASING AGREEMENT 
This Master Intergovernmental Cooperative Purchasing Agreement (this “Agreement”) is 
entered into by and between those certain government agencies that execute a Principal 
Procurement Agency Certificate (“Principal Procurement Agencies”) with National 
Intergovernmental Purchasing Alliance Company, a Delaware corporation d/b/a OMNIA 
Partners, Public Sector, Communities Program Management, LLC, a California limited 
liability company d/b/a U.S. Communities, and/or NCPA LLC, a Texas limited liability 
company d/b/a National Cooperative Purchasing Alliance (collectively, “OMNIA Partners”), 
in its capacity as the cooperative administrator, to be appended and made a part hereof and 
such other agencies (“Participating Public Agencies”), as defined in each Master 
Agreement (as defined below), who register to participate in the cooperative purchasing 
programs administered by OMNIA Partners and its affiliates and subsidiaries (collectively,
the “OMNIA Partners Parties”) by either registering on the OMNIA Partners website 
(www.omniapartners.com/publicsector or any successor website), or by executing a copy 
of this Agreement. 
 
RECITALS 
WHEREAS, after a competitive solicitation and selection process by Principal Procurement
Agencies, in compliance with their own policies, procedures, rules and regulations, a 
number of suppliers have entered into “Master Agreements” (herein so called) to provide 
a variety of goods, products and services (“Products”) to the applicable Principal 
Procurement Agency and the Participating Public Agencies; 
WHEREAS, Master Agreements are made available by Principal Procurement Agencies 
through the OMNIA Partners Parties and provide that Participating Public Agencies may 
purchase Products on the same terms, conditions and pricing as the Principal Procurement 
Agency, subject to any applicable federal and/or local purchasing ordinances and the laws 
of the State of purchase; and 
WHEREAS, in addition to Master Agreements, the OMNIA Partners Parties may from time 
to time offer Participating Public Agencies the opportunity to acquire Products through other 
group purchasing agreements. 
NOW, THEREFORE, in consideration of the mutual promises contained in this Agreement, 
and of the mutual benefits to result, the parties hereby agree as follows:
1. 
Each party will facilitate the cooperative procurement of Products. 
 
2. 
The Participating Public Agencies shall procure Products in accordance with 
and subject to the relevant federal, state and local statutes, ordinances, rules and regulations 
that govern Participating Public Agency’s procurement practices. The Participating Public 
Agencies hereby acknowledge and agree that it is the intent of the parties that all provisions 
of this Agreement and that Principal Procurement Agencies’ participation in the program 
described herein comply with all applicable laws, including but not limited to the requirements

Version June 28, 2023 
2024056 
 
 
 
 
Page 27 of 74 
Exhibit F 
Federal Funds Certifications 
FEDERAL CERTIFICATIONS
ADDENDUM FOR AGREEMENT FUNDED BY U.S. FEDERAL GRANT
TO WHOM IT MAY CONCERN: 
 
Participating Agencies may elect to use federal funds to purchase under the Master Agreement. This form should be 
completed and returned. 
DEFINITIONS 
Contract means a legal instrument by which a non–Federal entity purchases property or services needed to carry out the project 
or program under a Federal award. The term as used in this part does not include a legal instrument, even if the non–Federal 
entity considers it a contract, when the substance of the transaction meets the definition of a Federal award or subaward 
Contractor means an entity that receives a contract as defined in Contract. 
 
Cooperative agreement means a legal instrument of financial assistance between a Federal awarding agency or pass-through 
entity and a non–Federal entity that, consistent with 31 U.S.C. 6302–6305: 
(a) Is used to enter into a relationship the principal purpose of which is to transfer anything of value from the Federal 
awarding agency or pass-through entity to the non–Federal entity to carry out a public purpose authorized by a law of 
the United States (see 31 U.S.C. 6101(3)); and not to acquire property or services for the Federal government or 
pass-through entity's direct benefit or use; 
(b) Is distinguished from a grant in that it provides for substantial involvement between the Federal awarding agency 
or pass-through entity and the non–Federal entity in carrying out the activity contemplated by the Federal award. 
(c) The term does not include: 
(1) A cooperative research and development agreement as defined in 15 U.S.C. 3710a; or 
(2) An agreement that provides only: 
(i) Direct United States Government cash assistance to an individual; 
(ii) A subsidy; 
(iii) A loan; 
(iv) A loan guarantee; or 
(v) Insurance. 
 
Federal awarding agency means the Federal agency that provides a Federal award directly to a non–Federal entity 
 
Federal award has the meaning, depending on the context, in either paragraph (a) or (b) of this section:  
(a)(1) The Federal financial assistance that a non–Federal entity receives directly from a Federal awarding agency or 
indirectly from a pass-through entity, as described in § 200.101 Applicability; or 
(2) The cost-reimbursement contract under the Federal Acquisition Regulations that a non–Federal entity 
receives directly from a Federal awarding agency or indirectly from a pass-through entity, as described in § 
200.101 Applicability. 
(b) The instrument setting forth the terms and conditions. The instrument is the grant agreement, cooperative 
agreement, other agreement for assistance covered in paragraph (b) of § 200.40 Federal financial assistance, or the 
cost-reimbursement contract awarded under the Federal Acquisition Regulations. 
(c) Federal award does not include other contracts that a Federal agency uses to buy goods or services from a 
contractor or a contract to operate Federal government owned, contractor operated facilities (GOCOs). 
(d) See also definitions of Federal financial assistance, grant agreement, and cooperative agreement. 
 
Non–Federal entity means a state, local government, Indian tribe, institution of higher education (IHE), or nonprofit organization 
that carries out a Federal award as a recipient or subrecipient.

Version June 28, 2023 
2024056 
 
 
 
 
Page 28 of 74 
 
Nonprofit organization means any corporation, trust, association, cooperative, or other organization, not including IHEs, that: 
(a) Is operated primarily for scientific, educational, service, charitable, or similar purposes in the public interest; 
(b) Is not organized primarily for profit; and 
(c) Uses net proceeds to maintain, improve, or expand the operations of the organization. 
 
Obligations means, when used in connection with a non–Federal entity's utilization of funds under a Federal award, orders 
placed for property and services, contracts and subawards made, and similar transactions during a given period that require 
payment by the non–Federal entity during the same or a future period. 
 
Pass-through entity means a non–Federal entity that provides a subaward to a subrecipient to carry out part of a Federal 
program. 
 
Recipient means a non–Federal entity that receives a Federal award directly from a Federal awarding agency to carry out an 
activity under a Federal program. The term recipient does not include subrecipients. 
 
Simplified acquisition threshold means the dollar amount below which a non–Federal entity may purchase property or 
services using small purchase methods. Non–Federal entities adopt small purchase procedures in order to expedite the 
purchase of items costing less than the simplified acquisition threshold. The simplified acquisition threshold is set by the Federal 
Acquisition Regulation at 48 CFR Subpart 2.1 (Definitions) and in accordance with 41 U.S.C. 1908. As of the publication of this 
part, the simplified acquisition threshold is $250,000, but this threshold is periodically adjusted for inflation. (Also see definition 
of § 200.67 Micro-purchase.) 
 
Subaward means an award provided by a pass-through entity to a subrecipient for the subrecipient to carry out part of a Federal 
award received by the pass-through entity. It does not include payments to a contractor or payments to an individual that is a 
beneficiary of a Federal program. A subaward may be provided through any form of legal agreement, including an agreement 
that the pass-through entity considers a contract. 
 
Subrecipient means a non–Federal entity that receives a subaward from a pass-through entity to carry out part of a Federal 
program; but does not include an individual that is a beneficiary of such program. A subrecipient may also be a recipient of other 
Federal awards directly from a Federal awarding agency. 
 
Termination means the ending of a Federal award, in whole or in part at any time prior to the planned end of period of 
performance. 
 
The following provisions may be required and apply when Participating Agency expends federal funds for any purchase resulting 
from this procurement process. Per FAR 52.204-24 and FAR 52.204-25, solicitations and resultant contracts shall contain the 
following provisions. 
 
52.204-24 Representation Regarding Certain Telecommunications and Video Surveillance Services or Equipment (Oct 
2020) 
The Offeror shall not complete the representation at paragraph (d)(1) of this provision if the Offeror has represented that it "does 
not provide covered telecommunications equipment or services as a part of its offered products or services to the Government in 
the performance of any contract, subcontract, or other contractual instrument" in paragraph (c)(1) in the provision at 52.204-26, 
Covered Telecommunications Equipment or Services—Representation, or in paragraph (v)(2)(i) of the provision at 52.212-3, 
Offeror Representations and Certifications-Commercial Items. The Offeror shall not complete the representation in paragraph 
(d)(2) of this provision if the Offeror has represented that it "does not use covered telecommunications equipment or services, or 
any equipment, system, or service that uses covered telecommunications equipment or services" in paragraph (c)(2) of the 
provision at 52.204-26, or in paragraph (v)(2)(ii) of the provision at 52.212-3. 
      (a) Definitions. As used in this provision— 
      Backhaul, covered telecommunications equipment or services, critical technology, interconnection arrangements, 
reasonable inquiry, roaming, and substantial or essential component have the meanings provided in the clause 52.204-25, 
Prohibition on Contracting for Certain Telecommunications and Video Surveillance Services or Equipment.

Version June 28, 2023 
2024056 
 
 
 
 
Page 29 of 74 
 (b) Prohibition. 
(1) Section 889(a)(1)(A) of the John S. McCain National Defense Authorization Act for Fiscal Year 2019 (Pub. L. 115-232) 
prohibits the head of an executive agency on or after August 13, 2019, from procuring or obtaining, or extending or renewing a 
contract to procure or obtain, any equipment, system, or service that uses covered telecommunications equipment or services as 
a substantial or essential component of any system, or as critical technology as part of any system. Nothing in the prohibition shall 
be construed to— 
             (i) Prohibit the head of an executive agency from procuring with an entity to provide a service that connects to the 
facilities of a third-party, such as backhaul, roaming, or interconnection arrangements; or 
                (ii) Cover telecommunications equipment that cannot route or redirect user data traffic or cannot permit visibility into 
any user data or packets that such equipment transmits or otherwise handles. 
           (2) Section 889(a)(1)(B) of the John S. McCain National Defense Authorization Act for Fiscal Year 2019 (Pub. L. 115-
232) prohibits the head of an executive agency on or after August 13, 2020, from entering into a contract or extending or renewing 
a contract with an entity that uses any equipment, system, or service that uses covered telecommunications equipment or services 
as a substantial or essential component of any system, or as critical technology as part of any system. This prohibition applies to 
the use of covered telecommunications equipment or services, regardless of whether that use is in performance of work under a 
Federal contract. Nothing in the prohibition shall be construed to— 
                (i) Prohibit the head of an executive agency from procuring with an entity to provide a service that connects to the 
facilities of a third-party, such as backhaul, roaming, or interconnection arrangements; or
(ii) Cover telecommunications equipment that cannot route or redirect user data traffic or cannot permit visibility into 
any user data or packets that such equipment transmits or otherwise handles. 
      (c) Procedures. The Offeror shall review the list of excluded parties in the System for Award Management (SAM) 
(https://www.sam.gov) for entities excluded from receiving federal awards for "covered telecommunications equipment or services". 
      (d) Representation. The Offeror represents that— 
           (1) It  will,  will not provide covered telecommunications equipment or services to the Government in the performance 
of any contract, subcontract or other contractual instrument resulting from this solicitation. The Offeror shall provide the additional 
disclosure information required at paragraph (e)(1) of this section if the Offeror responds "will" in paragraph (d)(1) of this section; 
and 
           (2) After conducting a reasonable inquiry, for purposes of this representation, the Offeror represents that— 
          It  does,  does not use covered telecommunications equipment or services, or use any equipment, system, or service 
that uses covered telecommunications equipment or services. The Offeror shall provide the additional disclosure information 
required at paragraph (e)(2) of this section if the Offeror responds "does" in paragraph (d)(2) of this section. 
      (e) Disclosures.  
(1) Disclosure for the representation in paragraph (d)(1) of this provision. If the Offeror has responded "will" in the representation 
in paragraph (d)(1) of this provision, the Offeror shall provide the following information as part of the offer. 
                (i) For covered equipment— 
                     (A) The entity that produced the covered telecommunications equipment (include entity name, unique entity 
identifier, CAGE code, and whether the entity was the original equipment manufacturer (OEM) or a distributor, if known); 
                     (B) A description of all covered telecommunications equipment offered (include brand; model number, such as 
OEM number, manufacturer part number, or wholesaler number; and item description, as applicable); and 
(C) Explanation of the proposed use of covered telecommunications equipment and any factors relevant to 
determining if such use would be permissible under the prohibition in paragraph (b)(1) of this provision. 
                (ii) For covered services— 
                     (A) If the service is related to item maintenance: A description of all covered telecommunications services offered 
(include on the item being maintained: Brand; model number, such as OEM number, manufacturer part number, or wholesaler 
number; and item description, as applicable); or 
                     (B) If not associated with maintenance, the Product Service Code (PSC) of the service being provided; and 
explanation of the proposed use of covered telecommunications services and any factors relevant to determining if such use would 
be permissible under the prohibition in paragraph (b)(1) of this provision. 
           (2) Disclosure for the representation in paragraph (d)(2) of this provision. If the Offeror has responded "does" in the 
representation in paragraph (d)(2) of this provision, the Offeror shall provide the following information as part of the offer: 
                (i) For covered equipment— 
                     (A) The entity that produced the covered telecommunications equipment (include entity name, unique entity 
identifier, CAGE code, and whether the entity was the OEM or a distributor, if known);

Version June 28, 2023 
2024056 
 
 
 
 
Page 30 of 74 
                     (B) A description of all covered telecommunications equipment offered (include brand; model number, such as 
OEM number, manufacturer part number, or wholesaler number; and item description, as applicable); and 
(C) Explanation of the proposed use of covered telecommunications equipment and any factors relevant to 
determining if such use would be permissible under the prohibition in paragraph (b)(2) of this provision. 
                (ii) For covered services— 
                     (A) If the service is related to item maintenance: A description of all covered telecommunications services offered 
(include on the item being maintained: Brand; model number, such as OEM number, manufacturer part number, or wholesaler 
number; and item description, as applicable); or 
                     (B) If not associated with maintenance, the PSC of the service being provided; and explanation of the proposed 
use of covered telecommunications services and any factors relevant to determining if such use would be permissible under the 
prohibition in paragraph (b)(2) of this provision. 
52.204-25 Prohibition on Contracting for Certain Telecommunications and Video Surveillance Services or Equipment 
(Aug 2020). 
 (a) Definitions. As used in this clause— 
 Backhaul means intermediate links between the core network, or backbone network, and the small subnetworks at the edge 
of the network (e.g., connecting cell phones/towers to the core telephone network). Backhaul can be wireless (e.g., microwave) or 
wired (e.g., fiber optic, coaxial cable, Ethernet). 
 Covered foreign country means The People’s Republic of China. 
 Covered telecommunications equipment or services means– 
 (1) Telecommunications equipment produced by Huawei Technologies Company or ZTE Corporation (or any subsidiary 
or affiliate of such entities); 
 (2) For the purpose of public safety, security of Government facilities, physical security surveillance of critical 
infrastructure, and other national security purposes, video surveillance and telecommunications equipment produced by Hytera 
Communications Corporation, Hangzhou Hikvision Digital Technology Company, or Dahua Technology Company (or any 
subsidiary or affiliate of such entities); 
 (3) Telecommunications or video surveillance services provided by such entities or using such equipment; or 
 (4) Telecommunications or video surveillance equipment or services produced or provided by an entity that the Secretary 
of Defense, in consultation with the Director of National Intelligence or the Director of the Federal Bureau of Investigation, 
reasonably believes to be an entity owned or controlled by, or otherwise connected to, the government of a covered foreign country. 
 Critical technology means– 
 (1) Defense articles or defense services included on the United States Munitions List set forth in the International Traffic 
in Arms Regulations under subchapter M of chapter I of title 22, Code of Federal Regulations; 
 (2) Items included on the Commerce Control List set forth in Supplement No. 1 to part 774 of the Export Administration 
Regulations under subchapter C of chapter VII of title 15, Code of Federal Regulations, and controlled- 
 (i) Pursuant to multilateral regimes, including for reasons relating to national security, chemical and biological 
weapons proliferation, nuclear nonproliferation, or missile technology; or 
 (ii) For reasons relating to regional stability or surreptitious listening; 
 (3) Specially designed and prepared nuclear equipment, parts and components, materials, software, and technology 
covered by part 810 of title 10, Code of Federal Regulations (relating to assistance to foreign atomic energy activities); 
 (4) Nuclear facilities, equipment, and material covered by part 110 of title 10, Code of Federal Regulations (relating to 
export and import of nuclear equipment and material); 
 (5) Select agents and toxins covered by part 331 of title 7, Code of Federal Regulations, part 121 of title 9 of such Code, 
or part 73 of title 42 of such Code; or 
 (6) Emerging and foundational technologies controlled pursuant to section 1758 of the Export Control Reform Act of 
2018 (50 U.S.C. 4817). 
 Interconnection arrangements means arrangements governing the physical connection of two or more networks to allow 
the use of another's network to hand off traffic where it is ultimately delivered (e.g., connection of a customer of telephone provider 
A to a customer of telephone company B) or sharing data and other information resources. 
 Reasonable inquiry means an inquiry designed to uncover any information in the entity's possession about the identity of 
the producer or provider of covered telecommunications equipment or services used by the entity that excludes the need to include 
an internal or third-party audit.

Version June 28, 2023 
2024056 
 
 
 
 
Page 31 of 74 
 Roaming means cellular communications services (e.g., voice, video, data) received from a visited network when unable to 
connect to the facilities of the home network either because signal coverage is too weak or because traffic is too high. 
Substantial or essential component means any component necessary for the proper function or performance of a piece of 
equipment, system, or service. 
 (b) Prohibition.   
(1) Section 889(a)(1)(A) of the John S. McCain National Defense Authorization Act for Fiscal Year 2019 (Pub. L. 115-232) 
prohibits the head of an executive agency on or after August 13, 2019, from procuring or obtaining, or extending or renewing a 
contract to procure or obtain, any equipment, system, or service that uses covered telecommunications equipment or services as 
a substantial or essential component of any system, or as critical technology as part of any system. The Contractor is prohibited 
from providing to the Government any equipment, system, or service that uses covered telecommunications equipment or services 
as a substantial or essential component of any system, or as critical technology as part of any system, unless an exception at 
paragraph (c) of this clause applies or the covered telecommunication equipment or services are covered by a waiver described 
in FAR 4.2104. 
 (2) Section 889(a)(1)(B) of the John S. McCain National Defense Authorization Act for Fiscal Year 2019 (Pub. L. 115-
232) prohibits the head of an executive agency on or after August 13, 2020, from entering into a contract, or extending or renewing 
a contract, with an entity that uses any equipment, system, or service that uses covered telecommunications equipment or services 
as a substantial or essential component of any system, or as critical technology as part of any system, unless an exception at 
paragraph (c) of this clause applies or the covered telecommunication equipment or services are covered by a waiver described 
in FAR 4.2104. This prohibition applies to the use of covered telecommunications equipment or services, regardless of whether 
that use is in performance of work under a Federal contract. 
 (c) Exceptions. This clause does not prohibit contractors from providing— 
 (1) A service that connects to the facilities of a third-party, such as backhaul, roaming, or interconnection arrangements; 
or 
 (2) Telecommunications equipment that cannot route or redirect user data traffic or permit visibility into any user data or 
packets that such equipment transmits or otherwise handles. 
 (d) Reporting requirement. 
(1) In the event the Contractor identifies covered telecommunications equipment or services used as a substantial or essential 
component of any system, or as critical technology as part of any system, during contract performance, or the Contractor is notified 
of such by a subcontractor at any tier or by any other source, the Contractor shall report the information in paragraph (d)(2) of this 
clause to the Contracting Officer, unless elsewhere in this contract are established procedures for reporting the information; in the 
case of the Department of Defense, the Contractor shall report to the website at https://dibnet.dod.mil. For indefinite delivery 
contracts, the Contractor shall report to the Contracting Officer for the indefinite delivery contract and the Contracting Officer(s) for 
any affected order or, in the case of the Department of Defense, identify both the indefinite delivery contract and any affected 
orders in the report provided at https://dibnet.dod.mil. 
 (2) The Contractor shall report the following information pursuant to paragraph (d)(1) of this clause 
 (i) Within one business day from the date of such identification or notification: the contract number; the order 
number(s), if applicable; supplier name; supplier unique entity identifier (if known); supplier Commercial and Government Entity 
(CAGE) code (if known); brand; model number (original equipment manufacturer number, manufacturer part number, or wholesaler 
number); item description; and any readily available information about mitigation actions undertaken or recommended. 
 (ii) Within 10 business days of submitting the information in paragraph (d)(2)(i) of this clause: any further available 
information about mitigation actions undertaken or recommended. In addition, the Contractor shall describe the efforts it undertook 
to prevent use or submission of covered telecommunications equipment or services, and any additional efforts that will be 
incorporated to prevent future use or submission of covered telecommunications equipment or services. 
 (e) Subcontracts. The Contractor shall insert the substance of this clause, including this paragraph (e) and excluding 
paragraph (b)(2), in all subcontracts and other contractual instruments, including subcontracts for the acquisition of commercial 
items. 
The following certifications and provisions may be required and apply when Participating Agency expends federal funds for any 
purchase resulting from this procurement process. Pursuant to 2 C.F.R. § 200.326, all contracts, including small purchases, 
awarded by the Participating Agency and the Participating Agency’s subcontractors shall contain the procurement provisions of 
Appendix II to Part 200, as applicable.

Version June 28, 2023 
2024056 
 
 
 
 
Page 32 of 74 
 
APPENDIX II TO 2 CFR PART 200 
(A) Contracts for more than the simplified acquisition threshold currently set at $250,000, which is the inflation adjusted 
amount determined by the Civilian Agency Acquisition Council and the Defense Acquisition Regulations Council 
(Councils) as authorized by 41 U.S.C. 1908, must address administrative, contractual, or legal remedies in instances 
where contractors violate or breach contract terms, and provide for such sanctions and penalties as appropriate. 
Pursuant to Federal Rule (A) above, when a Participating Agency expends federal funds, the Participating Agency reserves all
rights and privileges under the applicable laws and regulations with respect to this procurement in the event of breach of contract 
by either party. 
Does offeror agree? YES   
Initials of Authorized Representative of 
offeror 
(B) Termination for cause and for convenience by the grantee or subgrantee including the manner by which it will be 
effected and the basis for settlement. (All contracts in excess of $10,000) 
Pursuant to Federal Rule (B) above, when a Participating Agency expends federal funds, the Participating Agency reserves the 
right to immediately terminate any agreement in excess of $10,000 resulting from this procurement process in the event of a 
breach or default of the agreement by Offeror as detailed in the terms of the contract. 
Does offeror agree?   YES   
Initials of Authorized Representative of 
offeror 
(C) Equal Employment Opportunity. Except as otherwise provided under 41 CFR Part 60, all contracts that meet the 
definition of “federally assisted construction contract” in 41 CFR Part 60-1.3 must include the equal opportunity clause 
provided under 41 CFR 60-1.4(b), in accordance with Executive Order 11246, “Equal Employment Opportunity” (30 
CFR 12319, 12935, 3 CFR Part, 1964-1965 Comp., p. 339), as amended by Executive Order 11375, “Amending Executive 
Order 11246 Relating to Equal Employment Opportunity,” and implementing regulations at 41 CFR part 60, “Office of 
Federal Contract Compliance Programs, Equal Employment Opportunity, Department of Labor.” 
Pursuant to Federal Rule (C) above, when a Participating Agency expends federal funds on any federally assisted construction 
contract, the equal opportunity clause is incorporated by reference herein. 
Does offeror agree to abide by the above?   YES   
Initials of Authorized Representative of offeror 
(D) Davis-Bacon Act, as amended (40 U.S.C. 3141-3148). When required by Federal program legislation, all prime 
construction contracts in excess of $2,000 awarded by non-Federal entities must include a provision for compliance 
with the Davis-Bacon Act (40 U.S.C. 3141-3144, and 3146-3148) as supplemented by Department of Labor regulations 
(29 CFR Part 5, “Labor Standards Provisions Applicable to Contracts Covering Federally Financed and Assisted 
Construction”). In accordance with the statute, contractors must be required to pay wages to laborers and mechanics 
at a rate not less than the prevailing wages specified in a wage determination made by the Secretary of Labor. In 
addition, contractors must be required to pay wages not less than once a week. The non-Federal entity must place a 
copy of the current prevailing wage determination issued by the Department of Labor in each solicitation. The decision 
to award a contract or subcontract must be conditioned upon the acceptance of the wage determination. The non 
- Federal entity must report all suspected or reported violations to the Federal awarding agency. The contracts must 
also include a provision for compliance with the Copeland “Anti-Kickback” Act (40 U.S.C. 3145), as supplemented by 
Department of Labor regulations (29 CFR Part 3, “Contractors and Subcontractors on Public Building or Public Work 
Financed in Whole or in Part by Loans or Grants from the United States”). The Act provides that each contractor or 
subrecipient must be prohibited from inducing, by any means, any person employed in the construction, completion, or 
repair of public work, to give up any part of the compensation to which he or she is otherwise entitled. The non -Federal 
entity must report all suspected or reported violations to the Federal awarding agency. 
Pursuant to Federal Rule (D) above, when a Participating Agency expends federal funds during the term of an award for all 
contracts and subgrants for construction or repair, offeror will be in compliance with all applicable Davis-Bacon Act provisions. 
Does offeror agree? YES   
Initials of Authorized Representative of offeror 
(E) Contract Work Hours and Safety Standards Act (40 U.S.C. 3701-3708). Where applicable, all contracts awarded by

Version June 28, 2023 
2024056 
 
 
 
 
Page 33 of 74 
the non-Federal entity in excess of $100,000 that involve the employment of mechanics or laborers must include a 
provision for compliance with 40 U.S.C. 3702 and 3704, as supplemented by Department of Labor regulations (29 CFR 
Part 5). Under 40 U.S.C. 3702 of the Act, each contractor must be required to compute the wages of every mechanic and 
laborer on the basis of a standard work week of 40 hours. Work in excess of the standard work week is permissible 
provided that the worker is compensated at a rate of not less than one and a half times the basic rate of pay for all 
hours worked in excess of 40 hours in the work week.  The requirements of 40 U.S.C.  3704 are applicable to construction 
work and provide that no laborer or mechanic must be required to work in surroundings or under working conditions 
which are unsanitary, hazardous or dangerous. These requirements do not apply to the purchases of supplies or 
materials or articles ordinarily available on the open market, or contracts for transportation or transmission of 
intelligence. 
Pursuant to Federal Rule (E) above, when a Participating Agency expends federal funds, offeror certifies that offeror will be in 
compliance with all applicable provisions of the Contract Work Hours and Safety Standards Act during the term of an award for 
all contracts by Participating Agency resulting from this procurement process. 
Does offeror agree? YES
Initials of Authorized Representative of offeror
(F) Rights to Inventions Made Under a Contract or Agreement. If the Federal award meets the definition of “funding 
agreement” under 37 CFR §401.2 (a) and the recipient or subrecipient wishes to enter into a contract with a small 
business firm or nonprofit organization regarding the substitution of parties, assignment or performance of 
experimental, developmental, or research work under that “funding agreement,” the recipient or subrecipient must 
comply with the requirements of 37 CFR Part 401, “Rights to Inventions Made by Nonprofit Organizations and Small 
Business Firms Under Government Grants, Contracts and Cooperative Agreements,” and any implementing regulations 
issued by the awarding agency. 
Pursuant to Federal Rule (F) above, when federal funds are expended by Participating Agency, the offeror certifies that during 
the term of an award for all contracts by Participating Agency resulting from this procurement process, the offeror agrees to 
comply with all applicable requirements as referenced in Federal Rule (F) above. 
Does offeror agree? YES   
Initials of Authorized Representative of offeror 
(G) Clean Air Act (42 U.S.C. 7401-7671q.) and the Federal Water Pollution Control Act (33 U.S.C. 1251-1387), as 
amended—Contracts and subgrants of amounts in excess of $150,000 must contain a provision that requires the non- 
Federal award to agree to comply with all applicable standards, orders or regulations issued pursuant to the Clean Air 
Act (42 U.S.C. 7401-7671q) and the Federal Water Pollution Control Act as amended (33 U.S.C. 1251- 1387). Violations 
must be reported to the Federal awarding agency and the Regional Office of the Environmental Protection Agency 
(EPA) 
In the event Federal Transit Administration (FTA) or Department of Transportation (DOT) funding is used by Participating Public 
Agency, Offeror also agrees to include Clean Air and Clean Water requirements in each subcontract exceeding $100,000 financed 
in whole or in part with Federal assistance provided by FTA. 
Pursuant to Federal Rule (G) above, when federal funds are expended by Participating Agency, the offeror certifies that during 
the term of an award for all contracts by Participating Agency member resulting from this procurement process, the offeror 
agrees to comply with all applicable requirements as referenced in Federal Rule (G) above. 
Does offeror agree? YES   
Initials of Authorized Representative of offeror 
(H) Debarment and Suspension (Executive Orders 12549 and 12689)—A contract award (see 2 CFR 180.220) must not be 
made to parties listed on the government wide exclusions in the System for Award Management (SAM), in accordance 
with the Executive Office of the President Office of Management and Budget (OMB) guidelines at 2 CFR 180 that 
implement Executive Orders 12549 (3 CFR part 1986 Comp., p. 189) and 12689 (3 CFR part 1989 Comp., p. 235), 
“Debarment and Suspension.” SAM Exclusions contains the names of parties debarred, suspended, or otherwise 
excluded by agencies, as well as parties declared ineligible under statutory or regulatory authority other than Executive 
Order 12549. 
Pursuant to Federal Rule (H) above, when federal funds are expended by Participating Agency, the offeror certifies that during 
the term of an award for all contracts by Participating Agency resulting from this procurement process, the offeror certifies that 
neither it nor its principals is presently debarred, suspended, proposed for debarment, declared ineligible, or voluntarily excluded

Version June 28, 2023 
2024056 
 
 
 
 
Page 34 of 74 
from participation by any federal department or agency.  If at any time during the term of an award the offeror or its principals 
becomes debarred, suspended, proposed for debarment, declared ineligible, or voluntarily excluded from participation by any 
federal department or agency, the offeror will notify the Participating Agency. 
Does offeror agree? YES   
Initials of Authorized Representative of offeror 
(I) Byrd Anti-Lobbying Amendment (31 U.S.C. 1352)—Contractors that apply or bid for an award exceeding $100,000 
must file the required certification. Each tier certifies to the tier above that it will not and has not used Federal 
appropriated funds to pay any person or organization for influencing or attempting to influence an officer or employee 
of any agency, a member of Congress, officer or employee of Congress, or an employee of a member of Congress in 
connection with obtaining any Federal contract, grant or any other award covered by 31 U.S.C. 1352. Each tier must 
also disclose any lobbying with non-Federal funds that takes place in connection with obtaining any Federal award. 
Such disclosures are forwarded from tier to tier up to the non-Federal award. 
Pursuant to Federal Rule (I) above, when federal funds are expended by Participating Agency, the offeror certifies that during 
the term and after the awarded term of an award for all contracts by Participating Agency resulting from this procurement 
process, the offeror certifies that it is in compliance with all applicable provisions of the Byrd Anti-Lobbying Amendment (31 
U.S.C. 1352). The undersigned further certifies that: 
(1)  No Federal appropriated funds have been paid or will be paid, by or on behalf of the undersigned, to any person for influencing 
or attempting to influence an officer or employee of any Federal agency, a Member of Congress, an officer or employee of 
Congress, or an employee of a Member of Congress in connection with the awarding of any Federal contract, the making of any 
Federal grant, the making of any Federal loan, the entering into of any cooperative agreement, and the extension, continuation, 
renewal, amendment, or modification of any Federal contract, grant, loan, or cooperative agreement. 
(2)  If any funds other than Federal appropriated funds have been paid or will be paid to any person for influencing or attempting 
to influence an officer or employee of any Federal agency, a Member of Congress, an officer or employee of Congress, or an 
employee of a Member of Congress in connection with this Federal contract, grant, loan, or cooperative agreement, the 
undersigned shall complete and submit Standard Form-LLL, "Disclosure of Lobbying Activities," in accordance with its instructions. 
This certification is a material representation of fact upon which reliance was placed when this transaction was made or entered 
into.  Submission of this certification is a prerequisite for making or entering into this transaction imposed by Section 1352, Title 
31, U.S. Code.  Any person who fails to file the required certification shall be subject to a civil penalty of not less than $10,000 and 
not more than $100,000 for each such failure. 
(3) The prospective participant also agrees by submitting his or her bid or proposal that he or she shall require that the language 
of this certification be included in all lower tier subcontracts, which exceed $100,000 and that all such subrecipients shall certify 
and disclose accordingly. 
 
Does offeror agree? YES
Initials of Authorized Representative of offeror
RECORD RETENTION REQUIREMENTS FOR CONTRACTS INVOLVING FEDERAL FUNDS 
When federal funds are expended by Participating Agency for any contract resulting from this procurement process, offeror 
certifies that it will comply with the record retention requirements detailed in 2 CFR § 200.333. The offeror further certifies that 
offeror will retain all records as required by 2 CFR § 200.333 for a period of three years after grantees or subgrantees 
submit final expenditure reports or quarterly or annual financial reports, as applicable, and all other pending matters are closed. 
 
Does offeror agree? YES   
Initials of Authorized Representative of offeror

Version June 28, 2023 
2024056 
 
 
 
 
Page 35 of 74 
 
CERTIFICATION OF COMPLIANCE WITH THE ENERGY POLICY AND CONSERVATION ACT 
When Participating Agency expends federal funds for any contract resulting from this procurement process, offeror certifies that
it will comply with the mandatory standards and policies relating to energy efficiency which are contained in the state energy 
conservation plan issued in compliance with the Energy Policy and Conservation Act (42 U.S.C. 6321 et seq.; 49 C.F.R. Part 18). 
 
Does offeror agree? YES   
Initials of Authorized Representative of offeror 
CERTIFICATION OF COMPLIANCE WITH BUY AMERICA PROVISIONS 
 
To the extent purchases are made with Federal Highway Administration, Federal Railroad Administration, or Federal Transit 
Administration funds, offeror certifies that its products comply with all applicable provisions of the Buy America Act and agrees to 
provide such certification or applicable waiver with respect to specific products to any Participating Agency upon request. 
Purchases made in accordance with the Buy America Act must still follow the applicable procurement rules calling for free and 
open competition. Additionally: 
 
(1) The Contractor agrees to comply with 49 USC 5323(j) and 49 CFR Part 661, which provide that federal funds may not 
be obligated unless steel, iron and manufactured products used in FTA-funded projects are produced in the United 
States, unless a waiver has been granted by FTA or the product is subject to a general waiver. General waivers are 
listed in 49 CFR 661.7.A general public interest waiver from the Buy America requirements applies to microprocessors, 
computers, microcomputers, software or other such devices, which are used solely for the purpose of processing or 
storing data. This general waiver does not extend to a product or device that merely contains a microprocessor or 
microcomputer and is not used solely for the purpose of processing or storing data. Separate requirements for rolling 
stock are set out at 5323(j)(2)(C) and 49 CFR 661.11. 
(2) A bidder or offeror must submit to the FTA recipient the appropriate Buy America certification with all bids on FTA-
funded contracts, except those subject to a general waiver. Bids or offers that are not accompanied by a completed 
Buy America certification must be rejected as nonresponsive. This requirement does not apply to lower tier 
subcontractors. 
 
The following certificates titled FTA and DOT Buy America Certification should be completed and returned with the response 
as part of FTA and DOT requirements. 
FEDERAL TRASIT ADMINISTRATION (FTA) AND DEPARTMENT OF TRANSPORTATION (DOT) - 
BUY AMERICA: CERTIFICATION REQUIREMENT FOR PROCUREMENTOF ROLLING STOCK 
CERTIFICATE OF COMPLIANCE  
(select one of the two options, NOT BOTH)  
Certificate of Compliance with 49 USC §5323(j)  
The proposer hereby certifies that it will comply with the requirements of 49 U.S.C. 5323(j), and the applicable regulations of 49 
CFR 661.11.  
Check for YES:  
  
OR

Version June 28, 2023 
2024056 
 
 
 
 
Page 36 of 74 
Certificate of Non-Compliance with 49 USC §5323(j)  
The proposer hereby certifies that it cannot comply with the requirements of 49 U.S.C. 5323(j), but may qualify for an exception to 
the requirement consistent with 49 U.S.C. 5323(j)(2)(C), and the applicable regulations in 49 CFR 661.7.  
Check for YES:  
 
FEDERAL TRASIT ADMINISTRATION (FTA) AND DEPARTMENT OF TRANSPORTATION (DOT) - 
BUY AMERICA: CERTIFICATION REQUIREMENT FOR PROCUREMENT OF STEEL OR MANUFACTURED PRODUCTS 
 
CERTIFICATE OF COMPLIANCE (select one of the two options, NOT BOTH)  
Certificate of Compliance with 49 USC §5323(j)(1)  
The proposer hereby certifies that it will comply with the requirements of 49 U.S.C. 5323(j)(1), and the applicable regulations in 49 
CFR part 661.  
Check for YES:  
 
OR  
 
Certificate of Non-Compliance with 49 USC §5323(j)(1)  
The proposer hereby certifies that it cannot comply with the requirements of 49 U.S.C. 5323(j), but it may qualify for an exception 
to the requirement pursuant to 49 U.S.C. 5323(j)(2), as amended, and the applicable regulations in 49 CFR 661.7.  
Check for YES:  
Does offeror agree? YES   
Initials of Authorized Representative of offeror 
Offeror’s Name: ___________________________________________________________________________________ 
Address, City, State, and Zip Code: ________________________________________________________________________ 
Phone Number:  __________________________________  
Fax Number: ______________________________________ 
Printed Name and Title of Authorized Representative:  _____________________________________________________________________ 
Email Address: __________________________________________________________________________________ 
Signature of Authorized Representative:  ____________________________________ 
Date: _____________________________ 
 
 
CERTIFICATION OF COMPLIANCE WITH BUY AMERICAN PROVISIONS 
 
Unless Supplier is exempt (See FAR 25.103), when authorized by statute or explicitly indicated by Participating Public Agency, 
Buy American requirements will apply where only unmanufactured construction material mined or produced in the United States 
shall be used (see Subpart 25.6 – American Recovery and Reinvestment Act-Buy American statute for additional details). 
 
 
CERTIFICATION OF ACCESS TO RECORDS – 2 C.F.R. § 200.336 
 
Offeror agrees that the Inspector General of the Agency or any of their duly authorized representatives shall have access to any 
documents, papers, or other records of offeror that are pertinent to offeror’s discharge of its obligations under the Contract for 
the purpose of making audits, examinations, excerpts, and transcriptions. The right also includes timely and reasonable access 
to offeror’s personnel for the purpose of interview and discussion relating to such documents. 
Does offeror agree? YES   
Initials of Authorized Representative of offeror 
CERTIFICATION OF APPLICABILITY TO SUBCONTRACTORS 
 
Offeror agrees that all contracts it awards pursuant to the Contract shall be bound by the foregoing terms and conditions. 
 
Does offeror agree? YES   
Initials of Authorized Representative of offeror

Version June 28, 2023 
2024056 
 
 
 
 
Page 37 of 74 
COMMUNITY DEVELOPMENT BLOCK GRANTS 
 
Purchases made under this contract may be partially or fully funded with federal grant funds. Funding for this work may include 
Federal Funding sources, including Community Development Block Grant (CDBG) funds from the U.S. Department of Housing 
and Urban Development. When such funding is provided, Offeror shall comply with all terms, conditions and requirements 
enumerated by the grant funding source, as well as requirements of the State statutes for which the contract is utilized, whichever 
is the more restrictive requirement. When using Federal Funding, Offeror shall comply with all wage and latest reporting provisions 
of the Federal Davis-Bacon Act. HUD-4010 Labor Provisions also applies to this contract. 
 
Does offeror agree? YES 
Initials of Authorized Representative of offeror 
 
 
Offeror agrees to comply with all federal, state, and local laws, rules, regulations and ordinances, as applicable. It is 
further acknowledged that offeror certifies compliance with all provisions, laws, acts, regulations, etc. as 
specifically noted above. 
 
Offeror’s Name: 
____________________________________________________________________________________________ 
Address, City, State, and Zip Code: 
_____________________________________________________________________________ 
Phone Number:  _____________________________ Fax Number: ________________________________ 
Printed Name and Title of Authorized Representative:  
_____________________________________________________________________ 
Email Address: 
____________________________________________________________________________________________ 
Signature of Authorized Representative:  ____________________________________Date: _____________________________

Version June 28, 2023 
2024056 
 
 
 
 
Page 38 of 74 
FEMA AND ADDITIONAL FEDERAL FUNDING SPECIAL CONDITIONS 
 
Awarded Supplier(s) (also referred to as Contractors) may need to respond to events and losses where 
products and services are needed for the immediate and initial response to emergency situations such as, 
but not limited to, water damage, fire damage, vandalism cleanup, biohazard cleanup, sewage 
decontamination, deodorization, and/or wind damage during a disaster or emergency situation. By 
submitting a proposal, the Supplier is accepted these FEMA and Additional Federal Funding Special 
Conditions required by the Federal Emergency Management Agency (FEMA) and other federal entities.  
 
“Contract” in the below pages under FEMA AND ADDITIONAL FEDERAL FUNDING SPECIAL 
CONDITIONS is also referred to and defined as the “Master Agreement”. 
 
“Contractor” in the below pages under FEMA AND ADDITIONAL FEDERAL FUNDING SPECIAL 
CONDITIONS is also referred to and defined as “Supplier” or “Awarded Supplier”. 
 
Conflicts of Interest 
No employee, officer, or agent may participate in the selection, award, or administration of a contract 
supported by a FEMA award if he or she has a real or apparent conflict of interest. Such a conflict would 
arise when the employee, officer, or agent, any member of his or her immediate family, his or her partner, 
or an organization which employs or is about to employ any of these parties, has a financial or other interest 
in or a tangible personal benefit from a firm considered for award. 2 C.F.R. § 200.318(c)(1); See also 
Standard Form 424D, ¶ 7; Standard Form 424B, ¶ 3. i. FEMA considers a “financial interest” to be the 
potential for gain or loss to the employee, officer, or agent, any member of his or her immediate family, his 
or her partner, or an organization which employs or is about to employ any of these parties as a result of 
the particular procurement. The prohibited financial interest may arise from ownership of certain financial 
instruments or investments such as stock, bonds, or real estate, or from a salary, indebtedness, job offer, 
or similar interest that might be affected by the particular procurement. ii. FEMA considers an “apparent” 
conflict of interest to exist where an actual conflict does not exist, but where a reasonable person with 
knowledge of the relevant facts would question the impartiality of the employee, officer, or agent 
participating in the procurement. c. Gifts. The officers, employees, and agents of the Participating Public 
Agency nor the Participating Public Agency (“NFE”) must neither solicit nor accept gratuities, favors, or 
anything of monetary value from contractors or parties to subcontracts. However, NFE’s may set standards 
for situations in which the financial interest is de minimus, not substantial, or the gift is an unsolicited item 
of nominal value. 2 C.F.R. § 200.318(c)(1). d. Violations. The NFE’s written standards of conduct must 
provide for disciplinary actions to be applied for violations of such standards by officers, employees, or 
agents of the NFE. 2 C.F.R. § 200.318(c)(1). For example, the penalty for a NFE’s employee may be 
dismissal, and the penalty for a contractor might be the termination of the contract. 
 
Contractor Integrity 
A contractor must have a satisfactory record of integrity and business ethics. Contractors that are debarred 
or suspended, as described in and subject to the debarment and suspension regulations implementing 
Executive Order 12549, Debarment and Suspension (1986) and Executive Order 12689, Debarment and 
Suspension (1989) at 2 C.F.R. Part 180 and the Department of Homeland Security’s regulations at 2 C.F.R. 
Part 3000 (Non-procurement Debarment and Suspension), must be rejected and cannot receive contract 
awards at any level. 
 
Notice of Legal Matters Affecting the Federal Government  
In the event FTA or DOT funding is used by Participating Public Agency, Contractor agrees to: 
1) The Contractor agrees that if a current or prospective legal matter that may affect the Federal 
Government emerges, the Contractor shall promptly notify the Participating Public Agency of the 
legal matter in accordance with 2 C.F.R. §§ 180.220 and 1200.220.  
 
2) The types of legal matters that require notification include, but are not limited to, a major dispute, 
breach, default, litigation, or naming the Federal Government as a party to litigation or a legal 
disagreement in any forum for any reason.

Version June 28, 2023 
2024056 
 
 
 
 
Page 39 of 74 
 
3) The Contractor further agrees to include the above clause in each subcontract, at every tier, 
financed in whole or in part with Federal assistance provided by the FTA. 
 
Public Policy 
A contractor must comply with the public policies of the Federal Government and state, local government, 
or tribal government. This includes, among other things, past and current compliance with the:  
a. Equal opportunity and nondiscrimination laws  
b. Five affirmative steps described at 2 C.F.R. § 200.321(b) for all subcontracting under contracts supported 
by FEMA financial assistance; and FEMA Procurement Guidance June 21, 2016 Page IV- 7  
c. Applicable prevailing wage laws, regulations, and executive orders  
 
Affirmative Steps 
For any subcontracting opportunities, Contractor must take the following Affirmative steps: 
1.
Placing qualified small and minority businesses and women's business enterprises on solicitation 
lists; 
2. Assuring that small and minority businesses, and women's business enterprises are solicited 
whenever they are potential sources;
3. Dividing total requirements, when economically feasible, into smaller tasks or quantities to permit 
maximum participation by small and minority businesses, and women's business enterprises; 
4. Establishing delivery schedules, where the requirement permits, which encourage participation by 
small and minority businesses, and women's business enterprises; and 
5. Using the services and assistance, as appropriate, of such organizations as the Small Business 
Administration and the Minority Business Development Agency of the Department of Commerce. 
 
Prevailing Wage Requirements 
When applicable, the awarded Contractor (s) and any and all subcontractor(s) agree to comply with all laws 
regarding prevailing wage rates including the Davis-Bacon Act, applicable to this solicitation and/or 
Participating Public Agencies.  The Participating Public Agency shall notify the Contractor of the applicable 
pricing/prevailing wage rates and must apply any local wage rates requested. The Contractor and any 
subcontractor(s) shall comply with the prevailing wage rates set by the Participating Public Agency.  
 
Federal Requirements 
If products and services are issued in response to an emergency or disaster recovery the items below, 
located in this FEMA Special Conditions section of the Federal Funds Certifications, are activated and 
required when federal funding may be utilized. 
2 C.F.R. § 200.326 and 2 C.F.R. Part 200, Appendix II, Required Contract Clauses 
1. 
CONTRACT REMEDIES 
Contracts for more than the federal simplified acquisition threshold (SAT), the dollar amount below 
which an NFE may purchase property or services using small purchase methods, currently set at 
$250,000 for procurements made on or after June 20, 2018,4 must address administrative, 
contractual, or legal remedies in instances where contractors violate or breach contract terms and 
must provide for sanctions and penalties as appropriate.  
 
1.1 Applicability  
This contract provision is required for contracts over the SAT, currently set at $250,000 for 
procurements made on or after June 20, 2018. Although not required for contracts at or below the 
SAT, FEMA suggests including a remedies provision.

Version June 28, 2023 
2024056 
 
 
 
 
Page 40 of 74 
1.2 Additional Considerations  
For FEMA’s Assistance to Firefighters Grant (AFG) Program, recipients must include a penalty 
clause in all contracts for any AFG-funded vehicle, regardless of dollar amount. In that situation, 
the contract must include a clause addressing that non-delivery by the contract’s specified date or 
other vendor nonperformance will require a penalty of no less than $100 per day until such time 
that the vehicle, compliant with the terms of the contract, has been accepted by the recipient. This 
penalty clause should, however, account for force majeure or acts of God. AFG recipients should 
refer to the applicable year’s Notice of Funding Opportunity (NOFO) for additional information, 
which can be accessed at FEMA.gov. 
 
2.
TERMINATION FOR CAUSE AND CONVENIENCE
 
a. 
Standard. All contracts in excess of $10,000 must address termination for cause and for 
convenience by the non-Federal entity, including the manner by which it will be effected 
and the basis for settlement. See 2 C.F.R. Part 200, Appendix II(B). 
b.
Applicability. This requirement applies to all FEMA grant and cooperative agreement 
programs. 
 
3. 
EQUAL EMPLOYMENT OPPORTUNITY 
 
When applicable: 
 
a.
Standard. Except as otherwise provided under 41 C.F.R. Part 60, all contracts that meet 
the definition of “federally assisted construction contract” in 41 C.F.R. 
§ 60-1.3 must include the equal opportunity clause provided under 41 C.F.R. § 60- 1.4(b), 
in accordance with Executive Order 11246, Equal Employment Opportunity (30 Fed. Reg. 
12319, 12935, 3 C.F.R. Part, 1964-1965 Comp., p. 
339), as amended by Executive Order 11375, Amending Executive Order 11246 Relating 
to Equal Employment Opportunity, and implementing regulations at 41 
C.F.R. Part 60 (Office of Federal Contract Compliance Programs, Equal Employment 
Opportunity, Department of Labor). See 2 C.F.R. Part 200, Appendix II(C). 
 
b. Key Definitions. 
i. 
Federally Assisted Construction Contract. The regulation at 41 C.F.R. § 60- 
1.3 defines a “federally assisted construction contract” as any agreement or 
modification thereof between any applicant and a person for construction work which 
is paid for in whole or in part with funds obtained from the Government or borrowed 
on the credit of the Government pursuant to any Federal program involving a grant, 
contract, loan, insurance, or guarantee, or undertaken pursuant to any Federal 
program involving such grant, contract, loan, insurance, or guarantee, or any 
application or modification thereof approved by the Government for a grant, contract, 
loan, insurance, or guarantee under which the applicant itself participates in the 
construction work. 
 
ii. 
Construction Work. The regulation at 41 C.F.R. § 60-1.3 defines “construction work” 
as the construction, rehabilitation, alteration, conversion, extension, demolition or 
repair of buildings, highways, or other changes or improvements to real property,

Version June 28, 2023 
2024056 
 
 
 
 
Page 41 of 74 
iii. including facilities providing utility services. The term also includes the supervision, 
inspection, and other onsite functions incidental to the actual construction. 
 
c. 
Applicability. This requirement applies to all FEMA grant and cooperative agreement 
programs. 
 
d.
Required Language. The regulation at 41 C.F.R. Part 60-1.4(b) requires the insertion of 
the following contract clause. 
 
During the performance of this contract, the contractor agrees as follows: 
(1) The contractor will not discriminate against any employee or applicant for 
employment because of race, color, religion, sex, sexual orientation, gender identity, or 
national origin. The contractor will take affirmative action to ensure that applicants are 
employed, and that employees are treated during employment without regard to their 
race, color, religion, sex, sexual orientation, gender identity, or national origin. Such 
action shall include, but not be limited to the following: 
Employment, upgrading, demotion, or transfer; recruitment or recruitment advertising; 
layoff or termination; rates of pay or other forms of compensation; and selection for 
training, including apprenticeship. The contractor agrees to post in conspicuous places, 
available to employees and applicants for employment, notices to be provided setting 
forth the provisions of this nondiscrimination clause. 
(2) The contractor will, in all solicitations or advertisements for employees placed by or 
on behalf of the contractor, state that all qualified applicants will receive consideration 
for employment without regard to race, color, religion, sex, sexual orientation, gender 
identity, or national origin. 
(3) The contractor will not discharge or in any other manner discriminate against any 
employee or applicant for employment because such employee or applicant has inquired 
about, discussed, or disclosed the compensation of the employee or applicant or another 
employee or applicant. This provision shall not apply to instances in which an employee 
who has access to the compensation information of other employees or applicants as a 
part of such employee's essential job functions discloses the compensation of such other 
employees or applicants to individuals who do not otherwise have access to such 
information, unless such disclosure is in response to a formal complaint or charge, in 
furtherance of an investigation, proceeding, hearing, or action, including an investigation 
conducted by the employer, or is consistent with the contractor's legal duty to furnish 
information. 
 
(4) The contractor will send to each labor union or representative of workers with which 
he has a collective bargaining agreement or other contract or understanding, a notice to 
be provided advising the said labor union or workers' representatives of the contractor's 
commitments under this section and shall post copies of the notice in conspicuous 
places available to employees and applicants for employment. 
(5) The contractor will comply with all provisions of Executive Order 11246 of September 
24, 1965, and of the rules, regulations, and relevant orders of the Secretary of Labor. 
(6) The contractor will furnish all information and reports required by Executive Order 
11246 of September 24, 1965, and by rules, regulations, and orders of the Secretary of 
Labor, or pursuant thereto, and will permit access to his books, records, and accounts by 
the administering agency and the Secretary of Labor for purposes of investigation to 
ascertain compliance with such rules, regulations, and orders.

Version June 28, 2023 
2024056 
 
 
 
 
Page 42 of 74 
(7) In the event of the contractor's noncompliance with the nondiscrimination clauses of 
this contract or with any of the said rules, regulations, or orders, this contract may be 
canceled, terminated, or suspended in whole or in part and the contractor may be 
declared ineligible for further Government contracts or federally assisted construction 
contracts in accordance with procedures authorized in Executive Order 11246 of 
September 24, 1965, and such other sanctions may be imposed and remedies invoked 
as provided in Executive Order 11246 of September 24, 1965, or by rule, regulation, or 
order of the Secretary of Labor, or as otherwise provided by law. 
(8) The contractor will include the portion of the sentence immediately preceding 
paragraph (1) and the provisions of paragraphs (1) through (8) in every subcontract or 
purchase order unless exempted by rules, regulations, or orders of the Secretary of 
Labor issued pursuant to section 204 of Executive Order 11246 of September 24, 1965, 
so that such provisions will be binding upon each subcontractor or vendor. The 
contractor will take such action with respect to any subcontract or purchase order as the 
administering agency may direct as a means of enforcing such provisions, including 
sanctions for noncompliance:  
Provided, however, that in the event a contractor becomes involved in, or is threatened 
with, litigation with a subcontractor or vendor as a result of such direction by the 
administering agency, the contractor may request the United States to enter into such 
litigation to protect the interests of the United States. 
The applicant further agrees that it will be bound by the above equal opportunity clause 
with respect to its own employment practices when it participates in federally assisted 
construction work: Provided, That if the applicant so participating is a State or local 
government, the above equal opportunity clause is not applicable to any agency, 
instrumentality or subdivision of such government which does not participate in work on 
or under the contract. 
The applicant agrees that it will assist and cooperate actively with the administering 
agency and the Secretary of Labor in obtaining the compliance of contractors and 
subcontractors with the equal opportunity clause and the rules, regulations, and relevant 
orders of the Secretary of Labor, that it will furnish the administering agency and the 
Secretary of Labor such information as they may require for the supervision of such 
compliance, and that it will otherwise assist the administering agency in the discharge of 
the agency's primary responsibility for securing compliance. 
The applicant further agrees that it will refrain from entering into any contract or contract 
modification subject to Executive Order 11246 of September 24, 1965, with a contractor 
debarred from, or who has not demonstrated eligibility for, Government contracts and 
federally assisted construction contracts pursuant to the Executive Order and will carry 
out such sanctions and penalties for violation of the equal opportunity clause as may be 
imposed upon contractors and subcontractors by the administering agency or the 
Secretary of Labor pursuant to Part II, Subpart D of the Executive Order. In addition, the 
applicant agrees that if it fails or refuses to comply with these undertakings, the 
administering agency may take any or all of the following actions: Cancel, terminate, or 
suspend in whole or in part this grant (contract, loan, insurance, guarantee); refrain from 
extending any further assistance to the applicant under the program with respect to 
which the failure or refund occurred until satisfactory assurance of future compliance has 
been received from such applicant; and refer the case to the Department of Justice for 
appropriate legal proceedings.

Version June 28, 2023 
2024056 
 
 
 
 
Page 43 of 74 
4. 
DAVIS-BACON ACT 
 
a. 
Standard. All prime construction contracts in excess of $2,000 awarded by non- Federal 
entities must include a provision for compliance with the Davis-Bacon Act (40 U.S.C. §§ 3141-
3144 and 3146-3148) as supplemented by Department of Labor regulations at 29 C.F.R. Part 
5 (Labor Standards Provisions Applicable to Contracts Covering Federally Financed and 
Assisted Construction). See 2 C.F.R. Part 200, Appendix II(D). In accordance with the statute, 
contractors must be required to pay wages to laborers and mechanics at a rate not less than 
the prevailing wages specified in a wage determination made by the Secretary of Labor. In 
addition, contractors must be required to pay wages not less than once a week. 
 
b.
Applicability. The Davis-Bacon Act applies to the Emergency Management Preparedness 
Grant Program, Homeland Security Grant Program, Nonprofit Security Grant Program, Tribal 
Homeland Security Grant Program, Port Security Grant Program, and Transit Security Grant 
Program.  
 
c.
Requirements. If applicable, the non-federal entity must do the following: 
i. The non-Federal entity must place a copy of the current prevailing wage 
determination issued by the Department of Labor in each solicitation. The decision 
to award a contract or subcontract must be conditioned upon the acceptance of 
the wage determination. The non-Federal entity must report all suspected or 
reported violations to the Federal awarding agency. 
 
ii. Additionally, pursuant 2 C.F.R. Part 200, Appendix II(D), contracts subject to the 
Davis-Bacon Act, must also include a provision for compliance with the Copeland 
“Anti-Kickback” Act (40 U.S.C. § 3145), as supplemented by Department of Labor 
regulations at 29 C.F.R. Part 3 (Contractors and Subcontractors on Public 
Building or Public Work Financed in Whole or in Part by Loans or Grants from the 
United States). The Copeland Anti- Kickback Act provides that each contractor or 
subrecipient must be prohibited from inducing, by any means, any person 
employed in the construction, completion, or repair of public work, to give up any 
part of the compensation to which he or she is otherwise entitled. The non- 
Federal entity must report all suspected or reported violations to FEMA. 
 
iii. 
Include a provision for compliance with the Davis-Bacon Act (40 U.S.C. 3141-
3144, and 3146-3148) as supplemented by Department of Labor regulations (29 
CFR Part 5, “Labor Standards Provisions Applicable to Contracts Covering 
Federally Financed and Assisted Construction”). 
 
Suggested Language. The following provides a sample contract clause:  
Compliance with the Davis-Bacon Act. 
a. 
All transactions regarding this contract shall be done in 
compliance with the Davis-Bacon Act (40 U.S.C. 3141- 3144, and 
3146-3148) and the requirements of 29 C.F.R. pt. 5 as may be 
applicable. The contractor shall comply with 40 U.S.C. 3141-
3144, and 3146-3148 and the requirements of 29 C.F.R. pt. 5 as 
applicable.

Version June 28, 2023 
2024056 
 
 
 
 
Page 44 of 74 
b. Contractors are required to pay wages to laborers and mechanics 
at a rate not less than the prevailing wages specified in a wage 
determination made by the Secretary of Labor. 
 
c. 
Additionally, contractors are required to pay wages not less than 
once a week. 
 
5. 
COPELAND ANTI-KICKBACK ACT 
 
a. 
Standard. Recipient and subrecipient contracts must include a provision for compliance with 
the Copeland “Anti-Kickback” Act (40 U.S.C. 3145), as supplemented by Department of Labor 
regulations (29 CFR Part 3, “Contractors and Subcontractors on Public Building or Public 
Work Financed in Whole or in Part by Loans or Grants from the United States”). 
b.
Applicability. This requirement applies to all contracts for construction or repair work above 
$2,000 in situations where the Davis-Bacon Act also applies. It DOES NOT apply to the FEMA 
Public Assistance Program. 
 
c.
Requirements. If applicable, the non-federal entity must include a provision for compliance 
with the Copeland “Anti-Kickback” Act (40 U.S.C. § 3145), as supplemented by Department 
of Labor regulations at 29 C.F.R. Part 3 (Contractors and Subcontractors on Public Building 
or Public Work Financed in Whole or in Part by Loans or Grants from the United States). Each 
contractor or subrecipient must be prohibited from inducing, by any means, any person 
employed in the construction, completion, or repair of public work, to give up any part of the 
compensation to which he or she is otherwise entitled. The non-Federal entity must report all 
suspected or reported violations to FEMA. Additionally, in accordance with the regulation, 
each contractor and subcontractor must furnish each week a statement with respect to the 
wages paid each of its employees engaged in work covered by the Copeland Anti-Kickback 
Act and the Davis Bacon Act during the preceding weekly payroll period. The report shall be 
delivered by the contractor or subcontractor, within seven days after the regular payment 
date of the payroll period, to a representative of a Federal or State agency in charge at the 
site of the building or work. 
 
Sample Language. The following provides a sample contract clause: 
Compliance with the Copeland “Anti-Kickback” Act. 
a. 
Contractor. The contractor shall comply with 18 U.S.C. § 874, 40 U.S.C. 
§ 3145, and the requirements of 29 C.F.R. pt. 3 as may be applicable, 
which are incorporated by reference into this contract. 
 
b.
Subcontracts. The contractor or subcontractor shall insert in any 
subcontracts the clause above and such other clauses as FEMA may 
by appropriate instructions require, and also a clause requiring the 
subcontractors to include these clauses in any lower tier subcontracts. 
The prime contractor shall be responsible for the compliance by any 
subcontractor or lower tier subcontractor with all of these contract 
clauses. 
 
c. 
Breach. A breach of the contract clauses above may be grounds for 
termination of the contract, and for debarment as a contractor and 
subcontractor as provided in 29 C.F.R. §5.12.”

Version June 28, 2023 
2024056 
 
 
 
 
Page 45 of 74 
6. 
CONTRACT WORK HOURS AND SAFETY STANDARDS ACT 
 
a. 
Standard. Where applicable (see 40 U.S.C. §§ 3701-3708), all contracts awarded by the 
non-Federal entity in excess of $100,000 that involve the employment of mechanics or 
laborers must include a provision for compliance with 40 U.S.C. §§ 3702 and 3704, as 
supplemented by Department of Labor regulations at 29 C.F.R. Part 5. See 2 C.F.R. Part 
200, Appendix II(E). Under 40 U.S.C. § 3702, each contractor must be required to 
compute the wages of every mechanic and laborer on the basis of a standard work week 
of 40 hours. Work in excess of the standard work week is permissible provided that the 
worker is compensated at a rate of not less than one and a half times the basic rate of 
pay for all hours worked in excess of 40 hours in the work week. Further, no laborer or 
mechanic must be required to work in surroundings or under working conditions which 
are unsanitary, hazardous, or dangerous. 
 
b. 
Applicability. This requirement applies to all FEMA contracts awarded by the non- federal 
entity in excess of $100,000 under grant and cooperative agreement programs that involve 
the employment of mechanics or laborers. It is applicable to construction work. These 
requirements do not apply to the purchase of supplies or materials or articles ordinarily 
available on the open market, or contracts for transportation or transmission of 
intelligence. 
 
c. 
Suggested Language. The regulation at 29 C.F.R. § 5.5(b) provides contract clause 
language concerning compliance with the Contract Work Hours and Safety Standards 
Act. FEMA suggests including the following contract clause: 
 
Compliance with the Contract Work Hours and Safety Standards Act. 
(1) Overtime requirements. No contractor or subcontractor contracting for any part of 
the contract work which may require or involve the employment of laborers or mechanics 
shall require or permit any such laborer or mechanic in any workweek in which he or she 
is employed on such work to work in excess of forty hours in such workweek unless such 
laborer or mechanic receives compensation at a rate not less than one and one-half 
times the basic rate of pay for all hours worked in excess of forty hours in such workweek. 
 
(2) Violation; liability for unpaid wages; liquidated damages. In the event of any violation 
of the clause set forth in paragraph (b)(1) of this section the contractor and any 
subcontractor responsible therefor shall be liable for the unpaid wages. In addition, such 
contractor and subcontractor shall be liable to the United States (in the case of work 
done under contract for the District of Columbia or a territory, to such District or to such 
territory), for liquidated damages. Such liquidated damages shall be computed with 
respect to each individual laborer or mechanic, including watchmen and guards, 
employed in violation of the clause set forth in paragraph (b)(1) of this section, in the sum 
of $27 for each calendar day on which such individual was required or permitted to work 
in excess of the standard workweek of forty hours without payment of the overtime 
wages required by the clause set forth in paragraph (b)(1) of this section. 
(3) Withholding for unpaid wages and liquidated damages. The Federal agency or 
loan/grant recipient shall upon its own action or upon written request of an authorized 
representative of the Department of Labor withhold or cause to be withheld, from any 
moneys payable on account of work performed by the contractor or subcontractor under 
any such contract or any other Federal contract with the same prime contractor, or any 
other federally-assisted contract subject to the Contract Work Hours and Safety 
Standards Act, which is held by the same prime contractor, such sums as may be 
determined to be necessary to satisfy any liabilities of such contractor or subcontractor 
for unpaid wages and liquidated damages as provided in the clause set forth in

Version June 28, 2023 
2024056 
 
 
 
 
Page 46 of 74 
paragraph (b)(2) of this section. 
(4) Subcontracts. The contractor or subcontractor shall insert in any subcontracts the
clauses set forth in paragraph (b)(1) through (4) of this section and also a clause requiring 
the subcontractors to include these clauses in any lower tier subcontracts. The prime 
contractor shall be responsible for compliance by any subcontractor or lower tier 
subcontractor with the clauses set forth in paragraphs (b)(1) through (4) of this section. 
 
7. 
RIGHTS TO INVENTIONS MADE UNDER A CONTRACT OR AGREEMENT 
 
a. 
Standard. If the FEMA award meets the definition of “funding agreement” under 37C.F.R. 
§ 401.2(a) and the non-Federal entity wishes to enter into a contract with a small business 
firm or nonprofit organization regarding the substitution of parties, assignment or 
performance of experimental, developmental, or research work under that “funding 
agreement,” the non- Federal entity must comply with the requirements of 37 C.F.R. Part 
401 (Rights to Inventions Made by Nonprofit Organizations and Small Business Firms 
Under Government Grants, Contracts and Cooperative Agreements), and any 
implementing regulations issued by FEMA. See 2 C.F.R. Part 200, Appendix II(F). 
b. 
Applicability. This requirement applies to “funding agreements,” but it DOES NOT apply 
to the Public Assistance, Hazard Mitigation Grant Program, Fire Management Assistance 
Grant Program, Crisis Counseling Assistance and Training Grant Program, Disaster Case 
Management Grant Program, and Federal Assistance to Individuals and Households – 
Other Needs Assistance Grant Program, as FEMA awards under these programs do not 
meet the definition of “funding agreement.” 
 
c. 
Funding Agreements Definition. The regulation at 37 C.F.R. § 401.2(a) defines “funding 
agreement” as any contract, grant, or cooperative agreement entered into between any 
Federal agency, other than the Tennessee Valley Authority, and any contractor for the 
performance of experimental, developmental, or research work funded in whole or in part 
by the Federal government. This term also includes any assignment, substitution of 
parties, or subcontract of any type entered into for the performance of experimental, 
developmental, or research work under a funding agreement as defined in the first 
sentence of this paragraph. 
 
8. 
CLEAN AIR ACT AND THE FEDERAL WATER POLLUTION CONTROL ACT 
 
a. 
Standard. If applicable, contracts must contain a provision that requires the contractor to 
agree to comply with all applicable standards, orders, or regulations issued pursuant to 
the Clean Air Act (42 U.S.C. §§ 7401-7671q.) and the Federal Water Pollution Control Act 
as amended (33 U.S.C. §§ 1251-1387). Violations must be reported to FEMA and the 
Regional Office of the Environmental Protection Agency. See 2 C.F.R. Part 200, 
Appendix II(G). 
 
b. 
Applicability. This requirement applies to contracts awarded by a non-federal entity of 
amounts in excess of $150,000 under a federal grant. 
 
c. 
Suggested Language. The following provides a sample contract clause. 
Clean Air Act 
1.
The contractor agrees to comply with all applicable standards, orders or 
regulations issued pursuant to the Clean Air Act, as amended, 42 U.S.C. 
§ 7401 et seq.

Version June 28, 2023 
2024056 
 
 
 
 
Page 47 of 74 
2. The contractor agrees to report each violation to the Participating Public 
Agency and understands and agrees that the Participating Public Agency 
will, in turn, report each violation as required to assure notification to the 
Federal Emergency Management Agency, and the appropriate 
Environmental Protection Agency Regional Office. 
 
3. The contractor agrees to include these requirements in each subcontract 
exceeding $150,000 financed in whole or in part with Federal assistance 
provided by FEMA. 
 
Federal Water Pollution Control Act 
1. The contractor agrees to comply with all applicable standards, orders, or 
regulations issued pursuant to the Federal Water Pollution Control Act, as 
amended, 33 U.S.C. 1251 et seq. 
 
2. The contractor agrees to report each violation to the Participating Public 
Agency and understands and agrees that the Participating Public Agency 
will, in turn, report each violation as required to assure notification to the 
Federal Emergency Management Agency, and the appropriate 
Environmental Protection Agency Regional Office. 
 
3. The contractor agrees to include these requirements in each subcontract 
exceeding $150,000 financed in whole or in part with Federal assistance 
provided by FEMA. 
 
9. 
DEBARMENT AND SUSPENSION 
 
a. 
Standard. Non-Federal entities and contractors are subject to the debarment and 
suspension regulations implementing Executive Order 12549, Debarment and 
Suspension (1986) and Executive Order 12689, Debarment and Suspension (1989) at 2 
C.F.R. Part 180 and the Department of Homeland Security’s regulations at 2 C.F.R. Part 
3000 (Non-procurement Debarment and Suspension). 
 
b. 
Applicability. This requirement applies to all FEMA grant and cooperative 
agreement programs. 
 
c. 
Requirements. 
i. 
These regulations restrict awards, subawards, and contracts with certain parties 
that are debarred, suspended, or otherwise excluded from or ineligible for 
participation in Federal assistance programs and activities. See 2 C.F.R. Part 200, 
Appendix II(H); and 2 C.F.R. § 200.213. A contract award must not be made to 
parties listed in the SAM Exclusions. SAM Exclusions is the list maintained by the 
General Services Administration that contains the names of parties debarred, 
suspended, or otherwise excluded by agencies, as well as parties declared 
ineligible under statutory or regulatory authority other than Executive Order 12549. 
SAM exclusions can be accessed at www.sam.gov. See 2 C.F.R. § 180.530. 
ii. 
In general, an “excluded” party cannot receive a Federal grant award or a contract 
within the meaning of a “covered transaction,” to include subawards and 
subcontracts. This includes parties that receive Federal funding indirectly, such

Version June 28, 2023 
2024056 
 
 
 
 
Page 48 of 74 
as contractors to recipients and subrecipients. The key to the exclusion is whether 
there is a “covered transaction,” which is any non-procurement transaction 
(unless excepted) at either a “primary” or “secondary” tier. Although “covered 
transactions” do not include contracts awarded by the Federal Government for 
purposes of the non-procurement common rule and DHS’s implementing 
regulations, it does include some contracts awarded by recipients and 
subrecipients. 
 
iii.
Specifically, a covered transaction includes the following contracts for goods or 
services: 
 
1. 
The contract is awarded by a recipient or subrecipient in the amount of at 
least $25,000. 
 
2.
The contract requires the approval of FEMA, regardlessof amount.
 
3. 
The contract is for federally-required audit services. 
 
4. 
A subcontract is also a covered transaction if it is awarded by the 
contractor of a recipient or subrecipient and requires either the approval of 
FEMA or is in excess of $25,000. 
 
d. 
Suggested Language. The following provides a debarment and suspension clause. It 
incorporates an optional method of verifying that contractors are not excluded or 
disqualified. 
 
Suspension and Debarment 
(1) 
This contract is a covered transaction for purposes of 2 C.F.R. pt. 180 and 2 C.F.R. 
pt. 3000. As such, the contractor is required to verify that none of the contractor’s 
principals (defined at 2 C.F.R. § 180.995) or its affiliates (defined at 2 C.F.R. § 
180.905) are excluded (defined at 2 C.F.R. § 180.940) or disqualified (defined at 2 
C.F.R. § 180.935). 
 
(2) 
The contractor must comply with 2 C.F.R. pt. 180, subpart C and2 C.F.R. pt. 3000, 
subpart C, and must include a requirement to comply with these regulations in any 
lower tier covered transaction it enters into. 
 
(3) 
This certification is a material representation of fact relied upon by the Participating 
Public Agency. If it is later determined that the contractor did not comply with 2 
C.F.R. pt. 180, subpart C and 2 C.F.R. pt. 3000, subpart C, in addition to remedies 
available to the Participating Public Agency, the Federal Government may pursue 
available remedies, including but not limited to suspension and/or debarment. 
 
(4) 
The bidder or proposer agrees to comply with the requirements of 2 C.F.R. pt. 
180, subpart C and 2 C.F.R. pt. 3000, subpart C while this offer is valid and 
throughout the period of any contract that may arise from this offer. The bidder or 
proposer further agrees to include a provision requiring such compliance in its 
lower tier covered transactions. 
 
10. 
BYRD ANTI-LOBBYING AMENDMENT 
 
a. 
Standard. Each tier certifies to the tier above that it will not and has not used Federal 
appropriated funds to pay any person or organization for influencing or attempting to

Version June 28, 2023 
2024056 
 
 
 
 
Page 49 of 74 
influence an officer or employee of any agency, a Member of Congress, officer or 
employee of Congress, or an employee of a Member of Congress in connection with 
obtaining any Federal contract, grant or any other award covered by 31 U.S.C. § 1352. 
FEMA’s regulation at 44 C.F.R. Part 18 implements the requirements of 31 U.S.C. § 1352 
and provides, in Appendix A to Part 18, a copy of the certification that is required to be 
completed by each entity as described in 31 U.S.C. § 1352. Each tier must also disclose 
any lobbying with non-Federal funds that takes place in connection with obtaining any 
Federal award. Such disclosures are forwarded from tier to tier up to the Federal 
awarding agency. 
 
b. 
Applicability. This requirement applies to all FEMA grant and cooperative agreement 
programs. Contractors that apply or bid for a contract of $100,000 or more under a federal 
grant must file the required certification. See 2 C.F.R. Part 200, Appendix II(I); 31 U.S.C. 
§ 1352; and 44 C.F.R. Part 18. 
 
c. 
Suggested Language. 
Byrd Anti-Lobbying Amendment, 31 U.S.C. § 1352 (as amended) 
Contractors who apply or bid for an award of $100,000 or more shall file the required 
certification. Each tier certifies to the tier above that it will not and has not used Federal 
appropriated funds to pay any person or organization for influencing or attempting to 
influence an officer or employee of any agency, a Member of Congress, officer or 
employee of Congress, or an employee of a Member of Congress in connection with 
obtaining any Federal contract, grant, or any other award covered by 31 U.S.C. § 1352. 
Each tier shall also disclose any lobbying with non-Federal funds that takes place in 
connection with obtaining any Federal award. Such disclosures are forwarded from tier 
to tier up to the recipient who in turn will forward the certification(s) to the awarding 
agency. 
 
d. 
Required Certification. If applicable, contractors must sign and submit to the non-federal 
entity the following certification. 
 
APPENDIX A, 44 C.F.R. PART 18 – CERTIFICATION REGARDING LOBBYING 
Certification for Contracts, Grants, Loans, and Cooperative Agreements 
 
The undersigned certifies, to the best of his or her knowledge and belief, that: 
 
1. No Federal appropriated funds have been paid or will be paid, by or on behalf of the 
undersigned, to any person for influencing or attempting to influence an officer or 
employee of an agency, a Member of Congress, an officer or employee of Congress, 
or an employee of a Member of Congress in connection with the awarding of any 
Federal contract, the making of any Federal grant, the making of any Federal loan, 
the entering into of any cooperative agreement, and the extension, continuation, 
renewal, amendment, or modification of any Federal contract, grant, loan, or 
cooperative agreement. 
2. If any funds other than Federal appropriated funds have been paid or will be paid to 
any person for influencing or attempting to influence an officer or employee of any 
agency, a Member of Congress, an officer or employee of Congress, or an employee 
of a Member of Congress in connection with this Federal contract, grant, loan, or 
cooperative agreement, the undersigned shall complete and submit Standard Form-
LLL, “Disclosure Form to Report Lobbying,” in accordance with its instructions.

Version June 28, 2023 
2024056 
 
 
 
 
Page 50 of 74 
3. The undersigned shall require that the language of this certification be included in 
the award documents for all subawards at all tiers (including subcontracts, 
subgrants, and contracts under grants, loans, and cooperative agreements) and that 
all subrecipients shall certify and disclose accordingly. 
 
This certification is a material representation of fact upon which reliance was placed 
when this transaction was made or entered into. Submission of this certification is a 
prerequisite for making or entering into this transaction imposed by section 1352, title 
31, U.S. Code. Any person who fails to file the required certification shall be subject to a 
civil penalty of not less than $10,000 and not more than $100,000 for each such failure. 
The Contractor,  
, certifies or affirms the truthfulness and 
accuracy of each statement of its certification and disclosure, if any. In addition, the 
Contractor understands and agrees that the provisions of 31 U.S.C. Chap. 38, 
Administrative Remedies for False Claims and Statements, apply to this certification and 
disclosure, if any. 
Signature of Contractor’s Authorized Official  
Name and Title of Contractor’s Authorized Official 
Date

2024056 
 
 
 
 
 
Page 51 of 74
11. 
PROCUREMENT OF RECOVERED MATERIALS 
 
a. 
Standard. A non-Federal entity that is a state agency or agency of a political subdivision of a state 
and its contractors must comply with Section 6002 of the Solid Waste Disposal Act, as amended 
by the Resource Conservation and Recovery Act. See 2 C.F.R. Part 200, Appendix II(J); and 2 
C.F.R. § 200.322. 
 
b. 
Applicability. This requirement applies to all contracts awarded by a non- federal entity under FEMA 
grant and cooperative agreement programs. 
 
c. 
Requirements. The requirements of Section 6002 include procuring only items designated in 
guidelines of the EPA at 40 C.F.R. Part 247 that contain the highest percentage of recovered 
materials practicable, consistent with maintaining a satisfactory level of competition, where the 
purchase price of the item exceeds 
$10,000 or the value of the quantity acquired by the preceding fiscal year exceeded $10,000; 
procuring solid waste management services in a manner that maximizes energy and resource 
recovery; and establishing an affirmative procurement program for procurement of recovered 
materials identified in the EPA guidelines. 
 
d. 
Suggested Language. 
i. 
In the performance of this contract, the Contractor shall make maximum use of products 
containing recovered materials that are EPA-designated items unless the product cannot 
be acquired— 
1. 
Competitively within a timeframe providing for compliance with the contract 
performance schedule; 
2. 
Meeting contract performance requirements; or 
3. 
At a reasonable price. 
 
ii. 
Information about this requirement, along with the list of EPA- designated items, is 
available 
at 
EPA’s 
Comprehensive 
Procurement 
Guidelines 
web 
site, 
https://www.epa.gov/smm/comprehensive-procurement-guideline-cpg-program. 
iii. 
The Contractor also agrees to comply with all other applicable requirements of Section 
6002 of the Solid Waste Disposal Act.” 
 
12.       DOMESTIC PREFERENCES FOR PROCUREMENTS  
 
As appropriate, and to the extent consistent with law, CONTRACTOR should, to the greatest extent 
practicable under a federal award, provide a preference for the purchase, acquisition, or use of goods, 
products or materials produced in the United States. This includes, but is not limited to, iron, aluminum, steel, 
cement, and other manufactured products.  
 
Applicability For purchases in support of FEMA declarations and awards issued on or after November 12, 
2020, all FEMA recipients and subrecipients are required to include in all contracts and purchase orders for 
work or products a contract provision encouraging domestic preference for procurements.  
 
Domestic Preference for Procurements As appropriate, and to the extent consistent with law, the contractor 
should, to the greatest extent practicable, provide a preference for the purchase, acquisition, or use of goods, 
products, or materials produced in the United States. This includes, but is not limited to iron, aluminum, steel, 
cement, and other manufactured products. For purposes of this clause: Produced in the United States means, 
for iron and steel products, that all manufacturing processes, from the initial melting stage through the 
application of coatings, occurred in the United States. Manufactured products mean items and construction 
materials composed in whole or in part of non-ferrous metals such as aluminum; plastics and polymer-based 
products such as polyvinyl chloride pipe; aggregates such as concrete; glass, including optical fiber; and 
lumber.”

Version June 28, 2023 
2024056 
 
 
 
 
Page 52 of 74 
13.  ACCESS TO RECORDS 
 
a. Standard. All recipients, subrecipients, successors, transferees, and assignees must acknowledge 
and agree to comply with applicable provisions governing DHS access to records, accounts, 
documents, information, facilities, and staff. Recipients must give DHS/FEMA access to, and the 
right to examine and copy, records, accounts, and other documents and sources of information 
related to the federal financial assistance award and permit access to facilities, personnel, and other 
individuals and information as may be necessary, as required by DHS regulations and other 
applicable laws or program guidance. See DHS Standard Terms and Conditions: Version 8.1 (2018). 
Additionally, Section 1225 of the Disaster Recovery Reform Act of 2018 prohibits FEMA from 
providing reimbursement to any state, local, tribal, or territorial government, or private non-profit for 
activities made pursuant to a contract that purports to prohibit audits or internal reviews by the FEMA 
administrator or Comptroller General. 
 
Access to Records. The following access to records requirements apply to this contract: 
i.The Contractor agrees to provide Participating Public Agency, the FEMA Administrator, the 
Comptroller General of the United States, or any of their authorized representatives access 
to any books, documents, papers, and records of the Contractor which are directly pertinent 
to this contract for the purposes of making audits, examinations, excerpts, and transcriptions. 
ii.The Contractor agrees to permit any of the foregoing parties to reproduce by any means 
whatsoever or to copy excerpts and transcriptions as reasonably needed. 
iii. The Contractor agrees to provide the FEMA Administrator or his authorized representatives 
access to construction or other work sites pertaining to the work being completed under the 
contract. 
 
iv.In compliance with the Disaster Recovery Act of 2018, the Participating Public Agency and 
the Contractor acknowledge and agree that no language in this contract is intended to 
prohibit audits or internal reviews by the FEMA Administrator or the Comptroller General of 
the United States. 
 
4. 
CHANGES 
a. Standard. To be eligible for FEMA assistance under the non-Federal entity’s FEMA grant or 
cooperative agreement, the cost of the change, modification, change order, or constructive change 
must be allowable, allocable, within the scope of its grant or cooperative agreement, and reasonable 
for the completion of project scope. 
 
b. Applicability. FEMA recommends, therefore, that a non-Federal entity include a changes clause in its 
contract that describes how, if at all, changes can be made by either party to alter the method, price, 
or schedule of the work without breaching the contract. The language of the clause may differ 
depending on the nature of the contract and the end-item procured. 
 
15. DHS SEAL, LOGO, AND FLAGS 
 
a. Standard. Recipients must obtain permission prior to using the DHS seal(s), logos, crests, or 
reproductions of flags or likenesses of DHS agency officials. See DHS Standard Terms and 
Conditions: Version 8.1 (2018). 
 
b. Applicability. FEMA recommends that all non-Federal entities place in their contracts a provision that 
a contractor shall not use the DHS seal(s), logos, crests, or reproductions of flags or likenesses of 
DHS agency officials without specific FEMA pre-approval. 
 
c. “The contractor shall not use the DHS seal(s), logos, crests, or reproductions of flags or likenesses 
of DHS agency officials without specific FEMA pre-approval.

Version June 28, 2023 
2024056 
 
 
 
 
Page 53 of 74 
16. COMPLIANCE WITH FEDERAL LAW, REGULATIONS, AND EXECUTIVE ORDERS 
 
a. Standard. The recipient and its contractors are required to comply with all Federal laws, regulations, 
and executive orders. 
 
b. Applicability. FEMA recommends that all non-Federal entities place into their contracts an 
acknowledgement that FEMA financial assistance will be used to fund the contract along with the 
requirement that the contractor will comply with all applicable Federal law, regulations, executive 
orders, and FEMA policies, procedures, and directives. 
 
c. “This is an acknowledgement that FEMA financial assistance will be used to fund all or a portion of 
the contract. The contractor will comply with all applicable Federal law, regulations, executive orders, 
FEMA policies, procedures, and directives.” 
 
17. NO OBLIGATION BY FEDERAL GOVERNMENT 
 
a. Standard. FEMA is not a party to any transaction between the recipient and its contractor. FEMA is 
not subject to any obligations or liable to any party for any matter relating to the contract. 
 
b. Applicability. FEMA recommends that the non-Federal entity include a provision in its contract that 
states that the Federal Government is not a party to the contract and is not subject to any obligations 
or liabilities to the non-Federal entity, contractor, or any other party pertaining to any matter resulting 
from the contract. 
 
c. “The Federal Government is not a party to this contract and is not subject to any obligations or 
liabilities to the non-Federal entity, contractor, or any other party pertaining to any matter resulting 
from the contract.” 
 
18. PROGRAM FRAUD AND FALSE OR FRAUDULENT STATEMENTS OR RELATED ACTS 
 
a. Standard. Recipients must comply with the requirements of The False Claims Act (31 U.S.C. §§ 3729-
3733) which prohibits the submission of false or 
 fraudulent claims for payment to the federal government. See DHS Standard Terms and 
Conditions: Version 8.1 (2018); and 31 U.S.C. §§ 3801-3812, which details the administrative 
remedies for false claims and statements made. The non-Federal entity must include a provision 
in its contract that the contractor acknowledges that 31 U.S.C. Chap. 38 (Administrative Remedies 
for False Claims and Statements) applies to its actions pertaining to the contract. 
 
b. Applicability. FEMA recommends that the non-Federal entity include a provision in its contract that 
the contractor acknowledges that 31 U.S.C. Chap. 38 (Administrative Remedies for False Claims and 
Statements) applies to its actions pertaining to the contract. 
 
c. “The Contractor acknowledges that 31 U.S.C. Chap. 38 (Administrative Remedies for False Claims 
and Statements) applies to the Contractor’s actions pertaining to this contract.”  
 
d. In the event FTA or DOT funding is used by a Participating Public Agency, Contractor further 
acknowledges U.S. DOT regulations, “Program Fraud Civil Remedies,” 49 CFR Part 31, and apply 
to its actions pertaining to this Contract. Upon execution of the underlying Contract, Contractor 
certifies or affirms the truthfulness and accuracy of any statement it has made, it makes, it may make, 
or causes to me made, pertaining to the underlying Contract or the FTA assisted project for which 
this Contract Work is being performed. 
 
In addition to other penalties that may be applicable, Contractor further acknowledges that if it makes, 
or causes to be made, a false, fictitious, or fraudulent claim, statement, submission, or certification, 
the Federal Government reserves the right to impose the penalties of the Program Fraud Civil 
Remedies Act of 1986 on Contractor to the extent the Federal Government deems appropriate.  
 
Contractor also acknowledges that if it makes, or causes to me made, a false, fictitious, or fraudulent 
claim, statement, submission, or certification to the Federal Government under a contract connected

Version June 28, 2023 
2024056 
 
 
 
 
Page 54 of 74 
with a project that is financed in whole or in part with Federal assistance originally awarded by FTA 
under the authority of 49 U.S.C. § 5307, the Government reserves the right to impose the penalties 
of 18 U.S.C. § 1001 and 49 U.S.C. § 5307 (n)(1) on the Contractor, to the extent the Federal 
Government deems appropriate.  
 
Contractor agrees to include the above clauses in each subcontract financed in whole or in part with 
Federal assistance provided by FTA. It is further agreed that the clauses shall not be modified, except 
to identify the subcontractor who will be subject to the provisions. 
 
 
Offeror agrees to comply with all terms and conditions outlined in the FEMA Special Conditions section 
of this solicitation. 
 
Offeror’s Name: ______________________________________________ 
Address, City, State, and Zip Code: 
_____________________________________________________________________________ 
Phone Number: ________________________ Fax Number: ______________________________ 
Printed Name and Title of Authorized Representative: 
____________________________________________________________ 
Email Address: _____________________________________________ 
 
Signature of Authorized Representative: ____________________________________ 
 
Date: ________________________________

EXHIBIT 1
DRAFT AGREEMENT
Version June 28, 2023 
2024056 
 
 
 
 
Page 74 of 74 
EXHIBIT D 
SPECIAL TERMS AND CONDITIONS FOR FEDERAL FUNDS 
The Special Terms and Conditions for Federal Funds will be added here when Agreement is finalized.

Amazon Web Services (AWS)  
https://aws.amazon.com/agreement/ 
 
Google Cloud Platform (GCP)  
https://cloud.google.com/terms 
 
Microsoft Azure:  
https://azure.microsoft.com/en-us/support/legal/

[Project Name] 
Statement of Work 
For [Customer Name] 
SHI International Corp. 
SOW # [#] 
[Publish Date] 
Presented By 
{SHI-User} 
Account Executive, SHI  
{Email} 
 
Created By 
{Services Team Member} 
{Title} 
{Email}

STATEMENT OF WORK FOR  [CUSTOMER NAME] 
 
[PROJECT NAME]  
 
 
CONFIDENTIAL | SHI SOW2023 | PAGE 2 OF 13 
Table of Contents 
1 
Executive Summary ...................................................................................................................... 3 
2 
Project Description ....................................................................................................................... 3 
2.1 
In Scope ............................................................................................................................................... 3 
2.2 
Deliverables ......................................................................................................................................... 3 
2.3 
Project Specific Assumptions ............................................................................................................ 3 
2.4 
Project Specific Customer Responsibilities ...................................................................................... 3 
2.5 
Out of Scope ........................................................................................................................................ 3 
2.6 
Project Duration .................................................................................................................................. 4 
2.7 
Project Management .......................................................................................................................... 4 
2.8 
Resources and Skills ........................................................................................................................... 5 
2.9 
Success Criteria .................................................................................................................................. 5 
3 
Assumptions ................................................................................................................................ 6 
4 
Customer Responsibilities ............................................................................................................ 6 
5 
Duties of SHI ................................................................................................................................ 8 
6 
Change Control Process ............................................................................................................... 8 
7 
Project Initiation Process .............................................................................................................. 8 
8 
Price and Payment Schedule ......................................................................................................... 9 
8.1 
Credits or Discounts ........................................................................................................................... 9 
8.1.1 
Credits or Discount Terms: ........................................................................................................ 9 
8.2 
Payment Schedule .............................................................................................................................. 9 
8.3 
Travel Expenses ................................................................................................................................ 10 
8.4 
Billing Terms ...................................................................................................................................... 10 
8.4.1 
Exception ................................................................................................................................... 10 
8.5 
Final Acceptance ............................................................................................................................... 10 
9 
Terms and Conditions ................................................................................................................. 11 
10 
SOW Acceptance .................................................................................................................... 11 
11 
Confidential ............................................................................................................................ 12 
12 
Billing Information .................................................................................................................. 12 
13 
Project Location(s) & Contact Information ............................................................................... 12

STATEMENT OF WORK FOR  [CUSTOMER NAME] 
 
[PROJECT NAME]  
 
 
CONFIDENTIAL | SHI SOW2023 | PAGE 3 OF 13 
1 Executive Summary 
[This should be a high-level executive description of the project.] 
[Customer Name] (“Customer”) has engaged SHI International Corp. (“SHI”) to [brief phrase describing 
high level goal] (“Services”).  
 
2 Project Description 
SHI shall provide the following Services to Customer on a fixed cost basis. 
 
2.1 In Scope  
• 
Bulleted list of Scope items 
 
2.2 Deliverables  
[This section should include any tangible customer deliverables such as documents, plans, diagrams.] 
All documents included in this section will be provided to the Customer. 
• 
Bulleted List of Deliverables 
 
2.3 Project Specific Assumptions 
• 
Bulleted List of project assumptions specific to the success of this project 
 
2.4 Project Specific Customer Responsibilities 
• 
Bulleted List of Customer Responsibilities or prerequisites specific to the success of this project 
 
2.5 Out of Scope 
Any services not explicitly listed above as “In Scope” shall be considered out of scope for this project. 
Additionally, the areas that are out of scope for this project include, but are not limited to, the following 
list. If any of these items are required for your organization, they can be scoped separately. 
• 
Bulleted list of Out of Scope items

STATEMENT OF WORK FOR  [CUSTOMER NAME] 
 
[PROJECT NAME]  
 
 
CONFIDENTIAL | SHI SOW2023 | PAGE 4 OF 13 
2.6 Project Duration 
Project duration is defined as the entire time taken to complete the project, based on the resources 
allocated. The estimated project duration is [XX DAYS/WEEKS/MONTHS] *.   
SHI and the Customer will provide the required resources to deliver this project within the estimated 
duration. SHI and the Customer will allow for reasonable accommodations due to holidays, vacations, 
and unforeseen delays in deliveries. 
* Please be advised that the above timeframe is to provide a general timeline for delivery and is not a true 
reflection of the total man hours/effort involved for this engagement.  
 
2.7 Project Management  
[Replace if Partner is providing PM with their methodology.  If SHI is providing PM, please choose one 
of the following 3 options.] 
SHI will provide a Project Manager to work with the Customer to see the engagement through to 
completion.  The SHI Project Manager will cover items such as, but not limited to: 
Option 1 – Ex: Consulting, Onsite Services 
• 
Acting as a point of contact that will be responsible for monitoring project progress as described 
in this Statement of Work. 
• 
Conducting a project kick off. 
• 
Monitoring the budget and providing a monthly status update. 
• 
Executing change requests to project scope, schedule, and or cost as needed. 
• 
Initiating project closure to confirm deliverables were achieved and request project acceptance. 
 
Option 2 – Ex: Most standard engagements  
• 
Leading the engagement to achieve the scope as described in this Statement of Work. 
• 
Conducting a project kick off and creating a project schedule to ensure that the project is 
executed on time and on budget. 
• 
Responsible for coordinating resources based on the project scope and their expertise as well as 
establishing roles and responsibilities. 
• 
Communicating status updates which includes action items, issues and risks as well as 
developing and facilitating mitigation plans. 
• 
Executing change requests to project scope, schedule, and or cost as needed. 
• 
Acting as the single point of contact for any issues or escalations throughout the engagement. 
• 
Initiating project closure to confirm deliverables were achieved and request project acceptance. 
 
Option 3 – Multiphase high user count migrations 
 
• 
Determining which project methodologies to leverage in order to achieve the scope on time and 
within budget as described in this Statement of Work. 
• 
Assembly of the project team based on scope and expertise, establishing roles and 
responsibilities and then coordinating resources throughout the engagement to ensure tasks are 
executed appropriately.

STATEMENT OF WORK FOR  [CUSTOMER NAME] 
 
[PROJECT NAME]  
 
 
CONFIDENTIAL | SHI SOW2023 | PAGE 6 OF 13 
3 Assumptions 
[This section includes standard Assumptions and should not be edited.  Project-specific Assumptions 
may be listed in section 2.3] 
The project scope and associated price quoted within this Statement of Work are based on the following 
assumptions. Should any element(s) of these assumptions be lacking during execution of services, 
additional time and associated fees and expenses may be required to complete this Statement of Work. 
1. Minimum lead time for scheduling project kickoff meeting is fifteen (15) business days from our 
receipt of the signed SOW or fifteen (15) business days from the confirmed start date between 
SHI and Customer; whichever date is later.  Should you require more aggressive scheduling, 
please contact SHI to determine availability. 
2. Please note that the time designated for Knowledge Transfer is throughout the project. Customer 
is responsible for providing a resource or resources focused on this project and the extent of the 
knowledge transfer is dependent upon the availability of these resources. A maximum of two 
hours of dedicated knowledge transfer at the project’s conclusion will be provided unless 
otherwise noted within this Statement of Work. 
3. SHI is not responsible for delays caused by failures; including but not exclusive to systems, 
personnel or environmental causes or in receiving data from Customer. 
4. Any restrictions or requirements regarding the SHI consultants’ use of personal equipment must 
be stated in advance of the commencement of the project.  
5. All hardware and/or software and licensing required to perform the above services will be 
provided by and is the responsibility of Customer. All wiring, hardware, and software required to 
perform the above services are in working order. 
6. All parties agree that personnel shall not be asked to perform, nor volunteer to perform, 
engineering and/or consulting tasks that lie outside the skill sets and experience of personnel. 
Personnel have the right to decline on a service request if the request falls outside the scope of 
their experience and expertise. 
7. Project activity will be scheduled during the hours of 8:00 AM to 5:00 PM local time. Any work 
performed outside these hours must be previously agreed upon by both parties and scheduled in 
advance. 
8. All documentation will be delivered within fifteen (15) business days after the completion of the 
in-scope tasks or phases of the project. A standard document template will be utilized for this 
service delivery. 
 
4 Customer Responsibilities 
[This section includes standard SHI Responsibilities and should not be edited.  Project-specific 
Responsibilities may be listed in section 2.4] 
Both Customer and SHI are responsible for the successful execution of this engagement. Prior to the 
start of this SOW, Customer will indicate to SHI in writing a person to be the point of contact.  All project 
communications will be addressed to such point of contact (the “Customer Contact”). The Customer 
Contact is responsible for the following: 
1. Performing a full working backup prior to the commencement of services as SHI is not 
responsible for lost data. 
2. Ensuring all related information and communication regarding this project is done through the 
Project Manager as expeditiously as possible.

STATEMENT OF WORK FOR  [CUSTOMER NAME] 
 
[PROJECT NAME]  
 
 
CONFIDENTIAL | SHI SOW2023 | PAGE 8 OF 13 
5 Duties of SHI 
SHI shall provide the Services and the SHI Work Product during the term of this engagement in 
accordance with this SOW and these terms and conditions.    
1. SHI will provide all resources, facilities, management, labor, expertise, skills, tools, and equipment 
necessary for the performance of its obligations under this SOW.   
2. Without limiting the foregoing, SHI shall:  
a. keep the Customer Project Manager advised of the progress of the project and the status of 
the Deliverables;  
b. permit any designated representative of Customer periodically to review the work of SHI 
personnel performing Services and preparing Deliverables;  
c. perform the Services in a timely manner and provide the Deliverables in accordance with this 
Statement of Work; and  
d. keep accurate records of work performed on this Statement of Work, evidence of which SHI 
shall provide to Customer upon request. 
 
6 Change Control Process 
The “Change Control Process” is that process which shall govern changes to the scope, schedule or price 
of the Project during the life of the Project. The Change Control Process will apply to new components 
and to enhancements of existing components. The Change Control Process will commence at the start of 
the Project and will continue throughout the Project's duration. 
Under the Change Control Process, a written “Change Request” will be the vehicle for communicating any 
desired changes to the project. It will describe the proposed change; the reason for the change and the 
effect the change may have on the Project. The Project Manager of the requesting party will submit a 
written Change Request to the Project Manager for the other parties. 
SHI and Customer will review the change request. All parties must sign the approval portion of the 
Change Request to authorize the implementation of any change that affects the Project’s scope, schedule 
or price.  
 
7 Project Initiation Process 
Upon receipt of a signed SOW and Purchase Order, planning for the project will commence. A key step in 
the planning process is the Kickoff Meeting with Customer’s Team. 
In the kickoff meeting, the contents of the SOW will be reviewed. This is an opportunity for Customer’s 
team who will be involved with the project to understand the Project’s goals, tasks, deliverables, and 
timelines. 
Upon completion of the project kickoff meeting, minutes of the Kickoff meeting will be created based on 
the meeting discussion and distributed to Customer. Any changes to the project will be documented in 
these minutes. If Change Orders are necessary due to changes, that process will be initiated after the 
Kick-off meeting.

STATEMENT OF WORK FOR  [CUSTOMER NAME] 
 
[PROJECT NAME]  
 
 
CONFIDENTIAL | SHI SOW2023 | PAGE 10 OF 13 
8.3 Travel Expenses 
CHOOSE ONE OF THE FOLLOWING 
OPTION 1 
Travel expenses are not included in the above price. Any Expenses incurred will be billed as actual and 
receipts will be provided. Any travel must be pre-approved in advance by Customer (a pre-approval form 
will be submitted for signature prior to the trip). Expenses will adhere to SHI’s Travel and Expense policy 
or the Customer’s, if required. 
The estimated travel expenses for this project are $XX. 
OPTION 2 
No travel is required for this project. 
OPTION 3 
Travel and expenses are included in the above price. 
 
8.4 Billing Terms 
SHI will request the approval of Customer when a milestone (see Payment Schedule above) has been 
completed. Upon receipt of Customer’s approval, SHI will invoice Customer for the milestone.  All invoices 
are due and payable within 30 calendar days of the invoice date.  
Fees DO NOT include applicable taxes that must be collected.  Please allow for taxes that may apply to 
the work outlined in your Purchase Order. Tax will be applied to the address in the “Billing Information” 
section unless otherwise specified in “Exception” section below. 
*Update per section used* 
8.4.1 Exception  
**Select OPTION 1 “Taxes will be applied to the physical addresses where the work is performed.” when 
onsite field services are performed.  
OPTION 1 
Taxes will be applied to the physical addresses where work is performed. 
OPTION 2 
No exceptions apply.  
 
8.5 Final Acceptance 
At the completion of the work SHI will provide a “Project Acceptance Form” for execution by Customer. 
Customer’s signature on this form signifies the Customer’s Final Acceptance of the work, and agreement 
that all Deliverables have been completed in accordance with the SOW and the final invoice may be 
issued by SHI.  If the Customer does not so accept the Deliverables then Customer shall, within fifteen 
calendar days after receipt of the Project Acceptance Form, state specifically which Deliverables were not 
Final Accepted and why, and return the form to SHI for resolution. 
If Customer does not return the Project Acceptance Form within fifteen calendar days after the date of its 
transmittal, Customer shall be deemed to have Final Accepted the Deliverables, and consequently, the 
remainder of the Services, and SHI will invoice the Customer for the remainder of the price due to SHI.

Project Name 
Statement of Work 
For [Customer Name] 
Presented By 
SHIuser 
Account Executive, SHI  
{Email} 
 
Created By 
{Services Team Member} 
{Title} 
{Email} 
 
SHI International Corp. 
SOW # [#] 
Publish Date

STATEMENT OF WORK FOR [CUSTOMER NAME] 
 
 PROJECT NAME  
 
 
CONFIDENTIAL | SHI SOW2023| PAGE 2 OF 13 
Table of Contents 
1 
Executive Summary ...................................................................................................................... 3 
2 
Project Description ....................................................................................................................... 3 
2.1 
In Scope ............................................................................................................................................... 3 
2.2 
Deliverables ......................................................................................................................................... 3 
2.3 
Project Specific Assumptions ............................................................................................................ 3 
2.4 
Project Specific Customer Responsibilities ...................................................................................... 3 
2.5 
Out of Scope ........................................................................................................................................ 3 
2.6 
Project Duration .................................................................................................................................. 4 
2.7 
Project Management .......................................................................................................................... 4 
2.8 
Resources and Skills ........................................................................................................................... 5 
3 
Assumptions ................................................................................................................................ 6 
4 
Customer Responsibilities ............................................................................................................ 6 
5 
Duties of SHI ................................................................................................................................ 8 
6 
Change Control Process ............................................................................................................... 8 
7 
Project Initiation Process .............................................................................................................. 8 
8 
Price and Payment Information ..................................................................................................... 9 
8.1 
Credits or Discounts ........................................................................................................................... 9 
8.1.1 
Credits or Discount Terms: ........................................................................................................ 9 
8.2 
Travel Expenses ................................................................................................................................ 10 
8.3 
Billing Terms ...................................................................................................................................... 10 
8.3.1 
Exception ................................................................................................................................... 10 
8.4 
Final Acceptance ............................................................................................................................... 10 
9 
Terms and Conditions ................................................................................................................. 11 
10 
SOW Acceptance .................................................................................................................... 11 
11 
Confidential ............................................................................................................................ 12 
12 
Billing Information .................................................................................................................. 12 
13 
Project Location(s) & Contact Information ............................................................................... 12

STATEMENT OF WORK FOR [CUSTOMER NAME] 
 
 PROJECT NAME  
 
 
CONFIDENTIAL | SHI SOW2023| PAGE 3 OF 13 
1 Executive Summary 
[This should be a high-level executive description of the project.] 
[Customer Name] (“Customer”) has engaged SHI International Corp (“SHI”) to [brief phrase describing 
high level goal] (“Services”). 
 
2 Project Description 
SHI shall provide the following Services to Customer on a time and materials cost basis. 
 
2.1 In Scope 
• 
Bulleted list of In Scope items 
 
2.2 Deliverables 
[This section should include any tangible customer deliverables such as documents, plans, diagrams.] 
All documents included in this section will be provided to the Customer. 
• 
Bulleted List of Deliverables 
 
2.3 Project Specific Assumptions 
• 
Bulleted List of project assumptions specific to the success of this project 
 
2.4 Project Specific Customer Responsibilities 
• 
Bulleted List of Customer Responsibilities or prerequisites specific to the success of this project 
 
2.5 Out of Scope 
Any Services not explicitly listed above as “In Scope” shall be considered out of scope for this project. 
Additionally, the areas that are out of scope for this project include, but are not limited to, the following 
list. If any of these items are required for your organization, they can be scoped separately. 
• 
Bulleted list of Out of Scope items

STATEMENT OF WORK FOR [CUSTOMER NAME] 
 
 PROJECT NAME  
 
 
CONFIDENTIAL | SHI SOW2023| PAGE 4 OF 13 
2.6 Project Duration 
Project duration is defined as the entire time taken to complete the project, based on the resources 
allocated. The estimated project duration is [XX DAYS/WEEKS/MONTHS] *.   
SHI and the Customer will provide the required resources to deliver this project within the estimated 
duration. SHI and the Customer will allow for reasonable accommodations due to holidays, vacations, 
and unforeseen delays in deliveries.   
 
*Note that Time and Materials budgets and durations are estimates. The final duration of the Services is 
affected by the actual time provided by all resources against the budget.  
 
2.7 Project Management  
[Replace if Partner is providing PM with their methodology.  If SHI is providing PM, please choose one 
of the following 3 options.] 
SHI will provide a Project Manager to work with the Customer to see the engagement through to 
completion.  The SHI Project Manager will cover items such as, but not limited to: 
Option 1 – Ex: Consulting, Onsite Services 
• 
Acting as a point of contact that will be responsible for monitoring project progress as described 
in this Statement of Work. 
• 
Conducting a project kick off. 
• 
Monitoring the budget and providing a monthly status update. 
• 
Executing change requests to project scope, schedule, and or cost as needed. 
• 
Initiating project closure to confirm deliverables were achieved and request project acceptance. 
 
Option 2 – Ex: Most standard engagements  
• 
Leading the engagement to achieve the scope as described in this Statement of Work. 
• 
Conducting a project kick off and creating a project schedule to ensure that the project is 
executed on time and on budget. 
• 
Responsible for coordinating resources based on the project scope and their expertise as well as 
establishing roles and responsibilities. 
• 
Communicating status updates which includes action items, issues and risks as well as 
developing and facilitating mitigation plans. 
• 
Executing change requests to project scope, schedule, and or cost as needed. 
• 
Acting as the single point of contact for any issues or escalations throughout the engagement. 
• 
Initiating project closure to confirm deliverables were achieved and request project acceptance. 
 
Option 3 – Multiphase high user count migrations 
 
• 
Determining which project methodologies to leverage in order to achieve the scope on time and 
within budget as described in this Statement of Work.

STATEMENT OF WORK FOR [CUSTOMER NAME] 
 
 PROJECT NAME  
 
 
CONFIDENTIAL | SHI SOW2023| PAGE 6 OF 13 
3 Assumptions 
[This section includes standard Assumptions and should not be edited.  Project-specific Assumptions 
may be listed in section 2.3] 
The project scope and associated price quoted within this Statement of Work are based on the following 
assumptions. Should any element(s) of these assumptions be lacking during execution of Services, 
additional time and associated fees and expenses may be required to complete this SOW. 
1. Minimum lead time for scheduling Project Kickoff meeting is fifteen (15) business days from our 
receipt of the signed SOW or fifteen (15) business days from the confirmed start date between 
SHI and Customer; whichever date is later.  Should you require more aggressive scheduling, 
please contact SHI to determine availability. 
2. Please note that the time designated for knowledge transfer is throughout the engagement.  
Customer is responsible for providing a resource dedicated to this engagement and the extent of 
the knowledge transfer is dependent upon the availability of this resource.   
3. SHI is not responsible for delays caused by failures, including but not exclusive to systems, 
personnel, or environmental causes or in receiving data from Customer. 
4. Any restrictions or requirements regarding the engineer’s use of personal equipment must be 
stated in advance of the commencement of the engagement.  
5. All hardware and/or software and licensing required to perform the above Services will be 
provided by and is the responsibility of Customer. All wiring, hardware, and software required to 
perform the above Services are in working order. 
6. All parties agree that personnel shall not be asked to perform, nor volunteer to perform, 
engineering and/or consulting tasks that lie outside the skill sets and experience of personnel. 
Personnel have the right to decline on a service request if the request falls outside the scope of 
their experience and expertise. 
7. Project activity will be scheduled during the hours of 8:00 AM to 5:00 PM local time. Any work 
performed outside these hours is considered "overtime" and subject to overtime rates. Overtime 
Services must be previously agreed upon by both parties, scheduled in advance and will require a 
change order authorizing such charges. 
8. All documentation will be delivered within fifteen (15) business days after the completion of the 
in-scope tasks or phases of the project. A standard document template will be utilized for this 
service delivery. 
 
 
4 Customer Responsibilities 
[This section includes standard SHI Responsibilities and should not be edited.  Project-specific 
Responsibilities may be listed in section 2.4] 
Both Customer and SHI are responsible for the successful execution of this engagement. Prior to the 
start of this SOW, Customer will indicate to SHI in writing a person to be the point of contact.  All project 
communications will be addressed to such point of contact (the “Customer Contact”). The Customer 
Contact is responsible for the following: 
1. Performing a full working backup prior to the commencement of Services as SHI is not 
responsible for lost data.

STATEMENT OF WORK FOR [CUSTOMER NAME] 
 
 PROJECT NAME  
 
 
CONFIDENTIAL | SHI SOW2023| PAGE 8 OF 13 
5 Duties of SHI 
SHI shall provide the Services and the SHI Work Product during the term of this engagement in 
accordance with this SOW and these terms and conditions.   
1. SHI will provide all resources, facilities, management, labor, expertise, skills, tools, and equipment 
necessary for the performance of its obligations under this SOW.   
2. Without limiting the foregoing, SHI shall:  
a. keep the Customer Project Manager advised of the progress of the project and the status of 
the Deliverables;  
b. permit any designated representative of Customer periodically to review the work of SHI 
personnel performing Services and preparing Deliverables;  
c. perform the Services in a timely manner and provide the Deliverables in accordance with this 
Statement of Work; and  
d. keep accurate records of work performed on this Statement of Work, evidence of which SHI 
shall provide to Customer upon request. 
 
6 Change Control Process 
The “Change Control Process” is that process which shall govern changes to the scope, schedule or price 
of the Project during the life of the Project. The Change Control Process will apply to new components 
and to enhancements of existing components. The Change Control Process will commence at the start of 
the Project and will continue throughout the Project's duration. 
Under the Change Control Process, a written “Change Request” will be the vehicle for communicating any 
desired changes to the project. It will describe the proposed change; the reason for the change and the 
effect the change may have on the Project. The Project Manager of the requesting party will submit a 
written Change Request to the Project Manager for the other parties. 
SHI and Customer will review the change request. All parties must sign the approval portion of the 
Change Request to authorize the implementation of any change that affects the Project’s scope, schedule 
or price.  
 
7 Project Initiation Process 
Upon receipt of a signed SOW and Purchase Order, planning for the project will commence. A key step in 
the planning process is the Kickoff Meeting with Customer’s Team. 
In the kickoff meeting, the contents of the SOW will be reviewed. This is an opportunity for Customer’s 
team who will be involved with the project to understand the Project’s goals, tasks, deliverables, and 
timelines. 
Upon completion of the project kickoff meeting, minutes of the Kickoff meeting will be created based on 
the meeting discussion and distributed to Customer. Any changes to the project scope will be 
documented in these minutes. If Change Orders are necessary due to scope changes, that process will be 
initiated after the Kickoff meeting.

STATEMENT OF WORK FOR [CUSTOMER NAME] 
 
 PROJECT NAME  
 
 
CONFIDENTIAL | SHI SOW2023| PAGE 10 OF 13 
8.2 Travel Expenses 
CHOOSE ONE OF THE FOLLOWING 
OPTION 1 
Travel expenses are not included in the above price. Any Expenses incurred will be billed as actual and 
receipts will be provided. Any travel must be pre-approved in advance by Customer (a pre-approval form 
will be submitted for signature prior to the trip). Expenses will adhere to SHI’s Travel and Expense Policy 
or the Customer’s, if required. 
OPTION 2 
No travel is required for this project. 
 
8.3 Billing Terms 
Invoices are processed monthly. All invoices are due and payable within 30 calendar days of the invoice 
date.  
Fees DO NOT include applicable taxes that must be collected.  Please allow for taxes that may apply to 
the work outlined in your Purchase Order. Tax will be applied to the address in the “Billing Information” 
section unless otherwise specified in “Exception” section below. 
*Update per section used* 
8.3.1 Exception  
**Select OPTION 1 “Taxes will be applied to the physical addresses where the work is performed.” when 
onsite field Services are performed.  
OPTION 1 
Taxes will be applied to the physical addresses where work is performed. 
OPTION 2 
No exceptions apply. 
 
8.4 Final Acceptance 
At the completion of the work SHI will provide a “Project Acceptance Form” for execution by Customer. 
Customer’s signature on this form signifies the Customer’s Final Acceptance of the work, and agreement 
that all Deliverables have been completed in accordance with the SOW and the final invoice may be 
issued by SHI.  If the Customer does not so accept the Deliverables then Customer shall, within fifteen 
calendar days after receipt of the Project Acceptance Form, state specifically which Deliverables were not 
Final Accepted and why, and return the form to SHI for resolution. 
If Customer does not return the Project Acceptance Form within fifteen calendar days after the date of its 
transmittal, Customer shall be deemed to have Final Accepted the Deliverables, and consequently, the 
remainder of the Services, and SHI will invoice the Customer for the remainder of the price due to SHI.

Amazon Web Services Partner Package – US State 
and Local Government and Education 
Updated Q2 2023

“This document is provided for informational purposes only. It represents AWS’s current product offerings and 
practices as of the date of issue of this document and is subject to change. Customers are responsible for making 
their own independent assessment of the information in this document and any use of AWS’s products or services. 
This document does not create any warranties, representations, contractual commitments, conditions or assurances 
from AWS, its affiliates, suppliers or licensors. The responsibilities and liabilities of AWS to its customers are 
controlled by AWS agreements, and this document is not part of, nor does it modify, any agreement between AWS 
and its customers. For current prices for AWS services, please refer to the AWS website at www.aws.amazon.com.” 
 
 
 
 
 
Partner Package – US 
Submitted by: 
Amazon Web Services, Inc. 
410 Terry Avenue North 
Seattle, WA 98109-5210

AWS Partner Package – US State and Local Government and Education
 
Use or disclosure of data contained on this sheet is subject to the restriction on the title page of this document 
Q2 2023 
i 
 
Table of Contents 
1. 
AWS History and Overview ............................................................................................... 5 
2. 
State and Local Government and Education ................................................................... 7 
2.1. 
What You Can Do With AWS ....................................................................................... 7 
2.1.1. 
State and Local Government ............................................................................. 7 
2.1.2. 
Support for Remote Work and Learning ............................................................ 8 
2.1.3. 
Education .......................................................................................................... 8 
3. 
Benefits of Working with the AWS Partner Network (APN) ............................................. 9 
3.1. 
Benefits of APN for Customers .................................................................................... 9 
4. 
AWS Cloud Security ........................................................................................................ 10 
4.1. 
Shared Controls for Security and Compliance ............................................................ 12 
4.2. 
Data Privacy and Ownership ...................................................................................... 12 
4.3. 
Customer Control of Data Residency ......................................................................... 13 
5. 
Services Overview ........................................................................................................... 14 
5.1. 
Compute Services ...................................................................................................... 15 
5.2. 
Storage Services ........................................................................................................ 16 
5.3. 
Database Services ..................................................................................................... 16 
5.4. 
Analytics Services ...................................................................................................... 16 
5.5. 
Networking and Content Delivery Services ................................................................ 17 
5.6. 
Migration and Transfer Services ................................................................................ 17 
5.7. 
Management and Governance Services .................................................................... 17 
5.8. 
Security, Identity, and Compliance Services .............................................................. 17 
5.9. 
Developer Tools ......................................................................................................... 18 
5.10. ML and AI Services .................................................................................................... 18 
5.11. IoT Services ............................................................................................................... 18 
5.12. Mobile Services .......................................................................................................... 19 
5.13. Call Center Services .................................................................................................. 19 
5.14. Hybrid Services .......................................................................................................... 19 
5.15. Other Services ........................................................................................................... 20 
6. 
AWS Cloud Infrastructure ............................................................................................... 20 
6.1. 
Access to Physical Infrastructure and Data Center Facilities ...................................... 21 
6.2. 
Data Center Audits ..................................................................................................... 22 
6.3. 
Service Level Agreements ......................................................................................... 22 
6.4. 
Data Center Virtual Tours .......................................................................................... 23 
6.5. 
Data Center Security .................................................................................................. 23 
7. 
Automatic Scaling of Cloud Resources ......................................................................... 24 
7.1. 
Scaling ....................................................................................................................... 24 
7.2. 
Load Balancing .......................................................................................................... 24 
7.3. 
Monitoring and Alarms ............................................................................................... 25 
8. 
Architecting for High Availability and Reliability ........................................................... 25 
8.1. 
AWS Responsibility: Data Center Availability and Reliability ...................................... 26 
8.2. 
Customer Responsibility: Designing for Availability and Reliability ............................. 26 
8.3. 
Resources and Reference Architecture ...................................................................... 27 
8.4. 
Building Secure Solutions on AWS ............................................................................ 27

AWS Partner Package – US State and Local Government and Education
 
Use or disclosure of data contained on this sheet is subject to the restriction on the title page of this document 
Q2 2023 
ii 
 
8.5. 
Granting and Managing Account Access.................................................................... 28 
8.5.1. 
IAM Users ........................................................................................................ 28 
8.5.2. 
IAM Groups ..................................................................................................... 28 
8.5.3. 
IAM Roles ........................................................................................................ 29 
8.5.4. 
Identity Federation ........................................................................................... 29 
8.5.5. 
Setting Granular Permissions .......................................................................... 29 
8.5.6. 
Temporary Security Credentials ...................................................................... 29 
8.6. 
Tools for Logical Separation ....................................................................................... 29 
8.7. 
Tools for Encryption ................................................................................................... 30 
8.7.1. 
Protecting Data at Rest .................................................................................... 30 
8.7.2. 
Protecting Data in Transit ................................................................................ 30 
8.8. 
Automating Security and Compliance ........................................................................ 31 
8.9. 
Penetration Testing .................................................................................................... 31 
8.10. Data Breaches ........................................................................................................... 31 
9. 
AWS Training and Certification ....................................................................................... 31 
9.1. 
Benefits of Training and Certification .......................................................................... 32 
9.2. 
Approach to Training and Workforce Development .................................................... 32 
9.3. 
Learning Needs Analysis ........................................................................................... 33 
9.4. 
Modes of Training Delivery......................................................................................... 34 
9.5. 
AWS Certification ....................................................................................................... 35 
10. Achieving Compliance on AWS ...................................................................................... 36 
10.1. Certifications and Attestations .................................................................................... 37 
10.2. Laws, Regulations, and Privacy ................................................................................. 37 
10.2.1. 
FERPA ............................................................................................................ 37 
10.2.2. 
HIPAA/HITECH ............................................................................................... 38 
10.2.2.1. AWS and HIPAA ........................................................................................38 
10.2.2.2. HIPAA for AWS Partners ...........................................................................39 
10.2.3. 
IRS Pub 1075 .................................................................................................. 39 
10.2.4. 
VPAT/Section 508 ........................................................................................... 39 
10.2.4.1. AWS and VPAT/Section 508 ......................................................................39 
10.3. Alignments/Frameworks ............................................................................................. 40 
10.3.1. 
Criminal Justice Information Services .............................................................. 40 
10.3.1.1. AWS and CJIS ...........................................................................................40 
10.3.1.2. CJIS for AWS Partners ..............................................................................41 
10.3.2. 
Cloud Security Alliance .................................................................................... 41 
10.3.2.1. AWS and CSA ...........................................................................................41 
10.3.2.2. CSA for AWS Partners ...............................................................................41 
10.3.3. 
Federal Information Security Management Act ................................................ 41 
10.3.4. 
National Institute of Standards and Technology 800-53 ................................... 42 
10.3.4.1. AWS and NIST 800-53...............................................................................42 
10.3.4.2. NIST 800-53 for AWS Partners ..................................................................42 
10.3.5. 
Uptime Institute Tiers ....................................................................................... 43 
10.3.5.1. AWS and Uptime Institute Tiers .................................................................43 
10.3.5.2. Uptime Institute Tiers for AWS Partners .....................................................43 
11. Managing AWS Resources .............................................................................................. 44 
11.1. AWS Management Console ....................................................................................... 44 
11.2. Command Line Interface (CLI) ................................................................................... 44 
11.3. Management Tools .................................................................................................... 44 
12. Back-up and Disaster Recovery (DR) ............................................................................. 45

AWS Partner Package – US State and Local Government and Education
 
Use or disclosure of data contained on this sheet is subject to the restriction on the title page of this document 
Q2 2023 
iii 
 
12.1. Backup and Restore .................................................................................................. 46 
12.2. Pilot Light for Simple Recovery into AWS Warm Standby Solution ............................. 47 
12.3. Warm Standby Solution in AWS ................................................................................. 47 
12.4. Multi-Site Solution Deployed on AWS and Onsite ...................................................... 47 
13. Security Questionnaires .................................................................................................. 47 
14. AWS Public Sector Access Policy – Instructions .......................................................... 48 
 
List of Figures 
Figure 1: AWS Shared Responsibility Model. ............................................................................11 
Figure 2: Partner Model Determines Level of Involvement in Customer Responsibility. ............12 
Figure 3: AWS Services. ...........................................................................................................15 
Figure 4: AWS Regions and Availability Zones. ........................................................................21 
Figure 5. Regions and Availability Zones ..................................................................................21 
Figure 6: Auto Scaling and Elastic Load Balancing with Amazon CloudWatch alarms. .............25 
Figure 7: Fault Tolerant AWS Reference Architecture ...............................................................27 
Figure 8: Phases of Learning Continuum ..................................................................................33 
Figure 9: AWS Certification Programs .......................................................................................36 
Figure 10: RPO and RTO. .........................................................................................................46 
Figure 11: Spectrum of DR Options. .........................................................................................46 
Figure 12: 2022 Gartner Magic Quadrant for Cloud Infrastructure and Platform Services ....... A-2 
 
List of Tables 
Table 1: Benefits of the Cloud .................................................................................................... 5 
Table 2: Features of AWS Training and Certification Delivery ...................................................35 
Table 3: AWS SOC Reports .................................................................................................. C-12 
 
Appendices 
Appendix A. Industry Analyst Reports on AWS Market Position .............................................. A-1 
Appendix B. AWS Resources .................................................................................................. B-3 
Appendix C. Common AWS Certifications ............................................................................... C-7

AWS Partner Package – US State and Local Government and Education
 
Use or disclosure of data contained on this sheet is subject to the restriction on the title page of this document 
Q2 2023 
4 
 
How to Use this Document 
This document contains information on the most frequently requested proposal topics from our 
Amazon Web Services, Inc. (AWS) Partner Network (APN) Partners. Please reach out to your 
aligned AWS partner manager if you need additional information to meet specific request for 
proposal/quotation/tender, etc. (RFx) requirements. 
The content in this document is intended as informational material regarding AWS Cloud 
services that may be used to inform your responses to particular RFxs from your public sector 
customers. While AWS encourages you to rely on the Partner Package content to help you 
formulate your response, you may not attach the Partner Package to your response or copy and 
paste Partner Package content into your response without prior consent from AWS. Graphics or 
images may be copied and pasted into your response as long as: (1) clear and appropriate 
attribution is given to AWS or the third-party source of such images and (2) such images are 
copied in their entirety and without modification. You can refer to the cross-referenced RFx Aids 
at the top of each section for more information on the section’s topic. 
AWS is not a party to any contract resulting from a proposal or tender. As it relates to your RFx 
response, AWS is a supplier—not a subcontractor—and we are not submitting a joint response 
or co-drafting a project scope. Your response must be on your letterhead and in your voice. 
AWS cannot write your response—or any part of the response—on your behalf.

AWS Partner Package – US State and Local Government and Education
 
Use or disclosure of data contained on this sheet is subject to the restriction on the title page of this document 
Q2 2023 
8 
 
• Justice and public safety customers can use AWS to help them tackle public 
safety data needs like records management systems, digital investigation 
practices, and next generation 911 technology. 
• Digital government solutions on AWS can span open data initiatives, traffic 
analysis, citizen service improvements, and IoT-based smart city projects, such 
as early flood warning systems, predictive analytics for road maintenance, and 
efficient trash pickup. 
• Elections administrators, political campaigns, and civic organizations can 
leverage AWS to provide underlying elections infrastructure in a secure, cost-
effective, and scalable way.  
• AWS offers a business continuity solution called CloudEndure Disaster Recovery 
that minimizes downtime and data loss by providing fast, reliable, cloud-based 
disaster recovery. The solution continuously replicates applications from 
physical, virtual, or cloud-based infrastructure to a low-cost staging area that is 
automatically provisioned in any target AWS Region of choice. 
2.1.2. Support for Remote Work and Learning 
• Government agencies and educational institutions can quickly set up a cloud-
based contact center with Amazon Connect for IT helpdesks and other 
departments needing to provide inbound and outbound support. 
• If you need to deliver personal cloud desktops to support remote work scenarios, 
you can use Amazon WorkSpaces to provision either Windows or Linux desktops 
in just a few minutes and quickly scale to provide thousands of desktops to 
users, anywhere. 
• If you need to virtualize computer lab spaces to support online distance learning, 
you can centrally manage desktops and applications on Amazon AppStream 2.0 
and securely deliver them to any computer using a web browser.  
2.1.3. Education 
• K12 and Primary Education can use AWS for data center migration, student data 
and analytics, and streamlining district IT operations, among other use cases. 
• Higher Education Institutions can support on-demand campus-wide IT 
management, easily deploy big data solutions, reduce their overall IT costs, and 
accelerate their research timelines by focusing on science rather than 
infrastructure. 
• Join AWS Educate to access online learning modules for cloud computing to 
your students and virtual cloud labs to your faculty at no cost. 
• To help students gain industry-recognized certifications and prepare for in-
demand cloud jobs, higher education customers use AWS Academy, which 
offers a cloud-based curriculum for educators to stay current with cloud 
innovation and equip students with valuable cloud skills. 
• EdTechs can use AWS to build and launch solutions that help students learn, 
with the flexibility and agility needed to experiment.

AWS Partner Package – US State and Local Government and Education
 
Use or disclosure of data contained on this sheet is subject to the restriction on the title page of this document 
Q2 2023 
9 
 
3. Benefits of Working with the AWS Partner Network (APN) 
You can find more information and use cases at the AWS Partner Network website and our Customer 
Success Stories page.  
The AWS Partner Network (APN) provides an extensive community of partner companies that 
offer solutions in areas such as value-added software, developer tools, and consulting expertise 
to help deploy and manage mission-critical workloads in the AWS Cloud. The APN program 
provides technical, business, and marketing support for this growing partner community.  
The APN website includes information about our two types of partners: 
• 
AWS Consulting Partners: AWS Consulting Partners are professional services firms 
that help customers design, architect, build, migrate, and manage workloads and 
applications on the AWS Cloud. AWS Consulting Partners include System Integrators 
(SIs), strategic consultancies, agencies, Managed Service Providers (MSPs), and Value-
Added Resellers (VARs). 
• 
AWS Technology Partners: In addition to consulting services, customers can work with 
AWS Technology Partners that provide software solutions that are either hosted on, or 
integrated with, the AWS Cloud. AWS Technology Partners include Independent 
Software Vendors (ISVs) and vendors for Software as a Service (SaaS), Platform as a 
Service (PaaS), developer tools, management, and security. 
APN has 100,000 partners from over 150 countries, including partners with solutions and 
experience in delivering government, education, and nonprofit customer missions around the 
world. More information on APN, along with our directory of AWS Partners, can be found on the 
AWS Partner Network page.  
AWS also outlines recommended partner procurement practices in the Procurement Best 
Practices for Partners whitepaper, available on the APN. This white paper provides tactical 
guidance for AWS Partners to educate, advise and shape their customers to adopt cloud 
procurement industry standards in federal acquisitions. It also provides strategies for AWS 
Partners to promote their partner programs and competencies as a competitive differentiator 
during acquisition shaping. 
3.1. Benefits of APN for Customers 
Many of our customers work in tandem with AWS Consulting Partners and AWS Technology 
Partners in order to leverage their experience in areas such as value-added software, 
established business applications, developer tools, and consulting expertise. APN provides 
access to qualified partners that resell AWS Cloud services and/or provide technical services to 
design, architect, build, migrate, and manage workloads and applications on AWS.  
AWS Partners receive several benefits that distinguish them from other vendors and provide 
them with resources that assist their customers: 
• 
AWS Partners have access to resources such as training, service information, 
certifications, and other tools that help them to be experts in the AWS Cloud. These 
resources help AWS Partners be more competent and confident in the solutions they 
offer to customers.  
• 
AWS Partners have a direct line of access to AWS corporate resources—such as 
business developers, engineers, Solutions Architects, and more—to help build and 
enhance solutions that work the best for their customers. This level of support is not 
normally available to vendors and companies that do not participate in APN.

AWS Partner Package – US State and Local Government and Education
 
Use or disclosure of data contained on this sheet is subject to the restriction on the title page of this document 
Q2 2023 
10 
 
• 
AWS Partners can attain AWS Competencies based on their specialization in key AWS 
solution areas. Attainment of an AWS Competency, which requires meeting or 
exceeding several requirements and passing a rigorous third-party audit of capabilities, 
is a public indication of the AWS Partner’s ability to excel in an area of expertise. The 
AWS Public Sector Partner Program includes partners with solutions and experience in 
delivering on a combination of government, education, and non-profit customer missions 
around the world. 
• 
Specific to reselling AWS services, AWS offers the Solution Provider Program—
designed for systems integrators, managed service providers, value-added resellers, 
and other public sector partners—to resell AWS Services as part of a differentiated 
solution. Under this program, Authorized Solution Providers manage, service, support, 
and bill AWS accounts for end customers.The Solution Provider Program includes a 
tiered discount structure based on technical capabilities and success in driving a new 
business. It includes flexible contracting options to help meet unique end customer 
requirements, and it provides partners with multiple AWS Support models that align with 
most AWS partner practices. 
Visit the Engage with AWS Partners page to learn more about customer success stories with 
AWS Partners, learn more about AWS Partner specialties, and search for AWS Partners by 
service, industry, workload, or solution. The APN Journal page provides additional information 
on how AWS Partners are helping customers achieve success in the AWS Cloud. 
4. AWS Cloud Security 
You can find more information in RFx Aid – Shared Responsibility. 
Because our customers build systems on top of AWS Cloud infrastructure, security and 
compliance responsibilities are shared between AWS and the customer. This shared 
responsibility model can help relieve customers’ operational burden as AWS operates, 
manages, and controls the components from the host operating system and virtualization layer 
down to the physical security of the facilities in which the service operates. Customers control 
how they architect and secure their applications and data put on the AWS Cloud. AWS provides 
a wide array of security and compliance services, and customers should carefully consider the 
services used, integration of those services into their IT environment, and applicable laws and 
regulations. AWS’s shared responsibility/security model is depicted in Figure 1. More 
information on how to build secure solutions on AWS can be found in Section 7.

AWS Partner Package – US State and Local Government and Education
 
Use or disclosure of data contained on this sheet is subject to the restriction on the title page of this document 
Q2 2023 
11 
 
 
Figure 1: AWS Shared Responsibility Model. This model reflects the respective responsibilities that 
AWS and the customer each have for securing the cloud and the resources and data it holds. Other 
parties such as a software provider or AWS Partner may sometimes hold security responsibilities. 
This differentiation of responsibility is commonly referred to as security of the cloud versus 
security in the cloud. 
• 
AWS Responsibility (Security of the Cloud): AWS is responsible for protecting the 
infrastructure that runs all of the services offered on the AWS Cloud. This infrastructure 
is composed of the hardware, software, networking, and facilities that run AWS Cloud 
services.  
• 
Customer/APN Partner Responsibility (Security in the Cloud): Customers/AWS 
Partners assume responsibility and management of the guest operating system 
(including updates and security patches); other associated application software; 
configuration of the AWS-provided security group firewalls; and other security, change 
management, and logging features.  
AWS’s shared responsibility model is further explained on the AWS Compliance webpage.  
In partner-led acquisitions, there is another party to factor into this model—the partner. The level 
of CSP and customer responsibilities in the shared responsibility model depend on the cloud 
deployment model, as shown in Figure 2. For example, a reseller may pass along the same 
shared responsibility model while a managed service provider may take on many of the 
customer responsibilities in the Shared Responsibility Model. AWS Partners should encourage 
customers to be clear about their desired level of responsibility in a cloud procurement.

AWS Partner Package – US State and Local Government and Education
 
Use or disclosure of data contained on this sheet is subject to the restriction on the title page of this document 
Q2 2023 
12 
 
 
Figure 2: Partner Model Determines Level of Involvement in Customer Responsibility. Based on the 
type of partner support model, an AWS Partner may hold most, some, or none of the customer’s 
responsibilities in the AWS Shared Responsibility Model. 
4.1. Shared Controls for Security and Compliance 
Some controls apply to both the infrastructure layer (AWS responsibility) and customer layers 
(customer/APN Partner responsibility), but in completely separate contexts or perspectives. In a 
shared control, AWS provides the requirements for the infrastructure, and the customer/AWS 
Partner must provide their own control implementation within their use of AWS Cloud services. 
Examples of these shared controls include the following: 
• 
Patch Management: AWS is responsible for patching and fixing flaws within the 
infrastructure, but customers/AWS Partners are responsible for patching their guest 
operating systems and applications. 
• 
Configuration Management: AWS maintains the configuration of its infrastructure 
devices, but customers/AWS Partners are responsible for configuring their own guest 
operating systems, databases, and applications. 
• 
Awareness and Training: AWS trains AWS employees, but customer/AWS Partners 
must train their own employees. 
For example, services such as Amazon Elastic Compute Cloud (Amazon EC2), Amazon Virtual 
Private Cloud (Amazon VPC), and Amazon Simple Storage Service (Amazon S3) are 
categorized as infrastructure as a service (IaaS) and, as such, require the customer to perform 
all of the necessary security configuration and management tasks. If a customer deploys an 
Amazon EC2 instance, they are responsible for management of the guest operating system 
(including updates and security patches), any application software or utilities installed by the 
customer on the instances, and the configuration of the AWS-provided firewall (called a security 
group) on each instance. 
4.2. Data Privacy and Ownership 
Customers maintain control of their data, and they can choose where to store their data within 
the cloud to conform to their country’s data residency regulations. Customers own their data and 
choose the Region(s) in which they store their data. AWS does not a move customer data

AWS Partner Package – US State and Local Government and Education
 
Use or disclosure of data contained on this sheet is subject to the restriction on the title page of this document 
Q2 2023 
13 
 
unless the customer decides to move it. In addition, customers can build hybrid cloud 
architectures that integrate their on-premises and cloud operations for use cases such as data 
center extension and edge computing. Read more in our Data Residency policy perspectives 
whitepaper and Hybrid Cloud with AWS page. 
AWS Cloud services have been intentionally designed so that our customers (not AWS 
personnel) have complete control over their data and applications. Customers maintain 
ownership of their content, and they select which AWS Cloud services can process, store, and 
host their content. AWS does not access or use customers’ content for any purpose without 
their consent. AWS gives customers ownership and control over their content through simple, 
powerful tools that allow them to determine where their content will be stored, secure their 
content in transit and at rest, and manage their access to AWS Cloud services and resources 
for their users. AWS also implements responsible and sophisticated technical and physical 
controls that are designed to prevent unauthorized access to or disclosure of content.  
Four basic guidelines of data privacy and ownership on AWS include the following: 
• 
Access: Customers manage access to their content and user access to AWS Cloud 
services and resources. AWS provides an advanced set of access, encryption, and 
logging features to help them do this effectively (such as AWS CloudTrail). We do not 
access or use customers’ content for any purpose without their consent. Customer 
virtual instances are solely controlled by the customer who has full root access or 
administrative control over accounts, services, and applications. AWS personnel do not 
have the ability to log into customer instances. We never use customers’ content or 
derive information from it for marketing or advertising. 
• 
Geographical Location of Data: Customers choose the AWS Region(s) in which their 
content is stored. AWS does not move or replicate customers’ content outside of their 
chosen AWS Region(s) without their consent, except as legally required and as 
necessary to maintain the AWS Cloud services. 
• 
Security: Customers choose how their content is secured, including via tokenization, 
data decomposition, cyber detection, and encryption. AWS has developed a security 
assurance program that uses best practices for global privacy and data protection to 
help customers operate securely within AWS, and to make the best use of our security 
control environment. These security protections and control processes are 
independently validated by multiple third-party independent assessments. We also offer 
strong encryption for content in transit and at rest, and we provide customers the option 
to manage their own encryption keys. 
• 
Disclosure of Customer Content: We do not disclose customer content unless  
required to do so to comply with the law, or with a valid and binding order of a 
governmental or regulatory body. Unless we are prohibited from doing so or there is 
clear indication of illegal conduct in connection with the use of Amazon products or 
services, Amazon notifies customers before disclosing customer content so they can 
seek protection from disclosure. Additional information can be found in our latest 
transparency report and our Amazon Law Enforcement Guidelines.  
4.3. Customer Control of Data Residency 
AWS has taken steps to accommodate customer concerns and government mandates related 
to data residency—the requirement that all customer content processed and stored in an IT 
system remain within specific geographical borders. AWS data centers are secure by design 
based on our physical and environmental controls. Both Gartner and IDC concluded that the 
security posture of major cloud service providers (CSPs) is equal to or better than the best

AWS Partner Package – US State and Local Government and Education
 
Use or disclosure of data contained on this sheet is subject to the restriction on the title page of this document 
Q2 2023 
14 
 
enterprise data centers, and that security should no longer be considered a primary inhibitor to 
the adoption of public cloud services. In fact, customers benefit from the security native in the 
cloud. More information about AWS’s controls can be found at our website, or in Section 7. 
5. Services Overview  
You can find more information in RFx Aid – AWS Services. 
AWS has continually expanded its services to support virtually any cloud workload. We now 
have more than 200 fully featured services, with several highlighted in the following subsections 
and depicted in Figure 3. In addition, our AWS Documentation page provides user guides, 
developer guides, API references, and tutorials to help our customers and AWS Partners get 
started on AWS and learn more about our services. Reference architectures and architecture 
whitepapers are available at AWS Architecture Center. The AWS This is My Architecture web 
page houses innovative cloud architectures from customers and AWS Partners.

AWS Partner Package – US State and Local Government and Education
 
Use or disclosure of data contained on this sheet is subject to the restriction on the title page of this document 
Q2 2023 
19 
 
allow customers to control, manage, and secure large and diverse device fleets. Finally, our 
data services (AWS IoT Analytics, AWS IoT Events, and AWS IoT SiteWise) help customers 
extract value from IoT data. 
5.12.  Mobile Services 
AWS offers a suite of services for building and deploying mobile applications, including AWS 
Amplify for provisioning and managing backends for mobile applications, AWS Device Farm for 
app testing, and Amazon Pinpoint and Amazon Simple Notification Service (Amazon SNS) for 
customer engagement. 
5.13.  Call Center Services 
You can find more information in RFxAid – Amazon Connect. 
Amazon Connect provides a seamless omnichannel experience through a single unified contact 
center for voice and chat. Amazon Connect is a cloud-based contact center service developed 
from the same contact center technology used by Amazon customer service associates around 
the world to power millions of customer conversations. 
Contact center agents can use Amazon Connect to communicate with customers across 
channels like voice and live chat, without losing the account information, progress, or changing 
agents. Amazon Connect’s cloud-based, omnichannel functionality simplifies contact center 
operations, improves agent efficiency, and lowers costs for organizations seeking to enhance 
the customer experience. This includes a single set of tools for skills-based routing, powerful 
real-time and historical analytics, and intuitive management tools—all with pricing based on the 
resources used rather than capacity, agent seats, or maintenance.   
Amazon Connect integrates with the leading customer relationship management (CRM), 
workforce management (WFM), analytics, and helpdesk solutions so customer contact centers 
can embed the Amazon Connect agent experience into the applications agents already use.  
5.14. Hybrid Services 
AWS offers hybrid cloud services that can help customers integrate a mix of cloud, on-premises 
data centers, and edge locations. VMware Cloud on AWS is an integrated cloud offering jointly 
developed by AWS and VMware that allows organizations to seamlessly migrate and extend 
their on-premises VMware vSphere-based environments to the AWS Cloud. AWS Outposts is a 
hybrid cloud solution that brings the AWS infrastructure, services, APIs, management tools, and 
support to virtually any data center, co-location space, or on-premises facility. 
For migration and computing on the edge, AWS has the AWS Snow Family, a collection of 
physical devices that help migrate large amounts of data into and out of the cloud without 
depending on networks. The Snow Family, comprised of AWS Snowcone, AWS Snowball, and 
AWS Snowmobile, offers a number of physical devices and capacity points, most with built-in 
computing capabilities. These services help physically transport up to exabytes of data into and 
out of AWS, as described below.  
• 
AWS Snowcone: The smallest member of the AWS Snow Family of edge computing, 
edge storage, and data transfer devices, weighing in at 4.5 pounds (2.1 kg) with 8 
terabytes of usable storage. Snowcone is ruggedized, secure, and purpose-built for use 
outside of a traditional data center.  
• 
AWS Snowball: A data migration and edge computing device that comes in two device 
options: Compute Optimized and Storage Optimized. Snowball Edge Storage Optimized

AWS Partner Package – US State and Local Government and Education
 
Use or disclosure of data contained on this sheet is subject to the restriction on the title page of this document 
Q2 2023 
21 
 
 
Figure 4: AWS Regions and Availability Zones. AWS has 6 geographic regions and 22 Availability 
Zones across the United States. 
Figure 5 illustrates the relationship between regions and Availability Zones. 
 
 
Figure 5. Regions and Availability Zones 
The AWS products and services that are available in each Region are listed at the Region Table 
webpage. 
 
6.1. Access to Physical Infrastructure and Data Center Facilities 
You can find more information in RFx Aid – Data Center Security and Access.  
AWS does not disclose the exact location of data centers and does not allow data center access 
to customers, as this exposes a wide range of customers to physical access of a third party. To 
meet this customer need, an independent and competent auditor validates the presence and 
operation of controls as part of our System and Organization Controls (SOC 1) Type 2 report.

AWS Partner Package – US State and Local Government and Education
 
Use or disclosure of data contained on this sheet is subject to the restriction on the title page of this document 
Q2 2023 
22 
 
This broadly accepted third-party validation provides customers with the independent 
perspective of the effectiveness of controls in place. A list of FAQs on how to access SOC 
reports is available through AWS Artifact here. 
SOC reports are independent third-party examination reports that demonstrate how CSPs 
achieve key compliance controls and objectives. These reports help customers and their 
auditors understand the CSP infrastructure controls established to support operations and 
compliance. These third-party audits and attestations provide customers with assurance that the 
CSP maintains robust compliance controls and alleviates the need for customers to visit on-site 
facilities, thus enhancing CSP infrastructure security overall. See Appendix C for more 
information on SOC reports. 
6.2. Data Center Audits  
AWS only provides data center access and information to employees and contractors who have 
a legitimate business need for such privileges. As such, AWS does not allow data center access 
to customers, as this exposes a range of customers to physical access of an outside party.  
Instead of allowing customers to perform physical audits, AWS has an independent third party 
perform audits of its data centers. These audits are conducted in accordance with the Federal 
Risk and Authorization Management Program (FedRAMP), American Institute of Certified Public 
Accountants (AICPA): AT 801 (formerly Statement on Standards for Attestation Engagements 
[SSAE] 16), and International Standards for Assurance Engagements (ISAE) 3402 professional 
standards.  
The auditors produce a SOC 1 Type 2 report in connection with the audit. Independent reviews 
of data center physical security are also part of an International Organization for Standardization 
(ISO) 27001 audit, a Payment Card Industry (PCI) Data Security Standard (DSS) assessment, 
and an International Traffic in Arms Regulations (ITAR) audit. 
Our rigorous attention to auditing provides peace of mind to our customers. Much as a customer 
trusts a bank based on reputation and regulation by the Federal Deposit Insurance Corporation 
(FDIC), our customers trust the independent third-party audits described above. It is widely 
accepted that such accrediting organizations are competent and qualified to assure customer 
confidence and acceptance without a personal inspection and accreditation—or customers 
having to hire their own accreditor. 
To help fulfill customer-specific audit and regulatory requirements, we detail our controls on our 
Data Center website. 
6.3. Service Level Agreements 
You can find more information in RFx Aid – SLAs. 
AWS provides service level agreements (SLAs) that apply to customer use of specific services. 
Due to the rapidly evolving nature of AWS Cloud service offerings, our SLAs are best reviewed 
directly on our website here. In each service-specific SLA, we detail our general service 
commitment, including our monthly uptime percentage.  
Our utility-based cloud model, customers can use our cloud infrastructure and its components 
as software-defined endpoints. This allows customers to achieve the highest levels of 
availability, performance, elasticity, scale, and geographic distribution to meet business service 
level requirements.

AWS Partner Package – US State and Local Government and Education
 
Use or disclosure of data contained on this sheet is subject to the restriction on the title page of this document 
Q2 2023 
23 
 
6.4. Data Center Virtual Tours 
Customers and AWS Partners can take a virtual tour of our data centers to observe how we 
implement a layered security structure to keep our data centers secure. The following provides 
a list of each data center layer with a link to a virtual tour for each one.  
• 
Perimeter Layer: AWS data center physical security begins at the perimeter layer. This 
layer includes physical security features depending on the location, such as security 
guards, fencing, security feeds, intrusion detection technology, and other measures.  
• 
Infrastructure Layer: The infrastructure layer is the data center building and the 
equipment and systems that keep it running. Components like back-up power 
equipment, the HVAC system, and fire suppression equipment are all part of the 
infrastructure layer. These devices and systems help protect servers and data. 
• 
Data Layer: The data layer is the most critical point of protection because it is the only 
area that holds customer data. Protection begins by restricting access and maintaining a 
separation of privilege for each layer. In addition, we deploy threat detection devices, 
video surveillance, and system protocols, further safeguarding this layer. 
• 
Environmental Layer: The environmental layer is dedicated to environmental 
considerations from site selection and construction to operations and sustainability. AWS 
carefully chooses our data center locations to mitigate environmental risk such as 
flooding, extreme weather, and seismic activity.  
6.5. Data Center Security 
AWS’s data centers use innovative architectural and engineering approaches to ensures their 
security. Amazon has many years of experience in designing, constructing, and operating large-
scale data centers. This experience has been applied to the AWS Cloud. The following 
subsections address some of our customers’ frequently asked questions about our data center 
security. 
• 
Physical and Environmental Security: AWS data centers are housed in nondescript 
facilities for anonymity. Physical access is strictly controlled at both the perimeter and at 
building ingress points by professional security staff using video surveillance, intrusion 
detection systems, and other electronic means. Authorized staff must pass two-factor 
authentication a minimum of two times to access data center floors. All visitors and 
contractors are required to present identification and are signed in and continually 
escorted by authorized staff. AWS only provides data center access and information to 
employees and contractors who have a legitimate business need for such privileges. 
When an employee no longer has a business need for these privileges, his or her 
access is immediately revoked, even if they continue to be an employee of Amazon or 
AWS. All physical access to data centers by AWS employees is logged and audited. 
• 
Fire Detection and Suppression: Automatic fire detection and suppression equipment 
has been installed to reduce risk. The fire detection system utilizes smoke detection 
sensors in all data center environments, mechanical and electrical infrastructure spaces, 
chiller rooms and generator equipment rooms. These areas are protected by either wet-
pipe, double-interlocked pre-action, or gaseous sprinkler systems. 
• 
Power: The data center electrical power systems are designed to be fully redundant and 
maintainable without impact to operations 24 hours a day and seven days a week. 
Uninterruptible power supply (UPS) units provide backup power in the event of an 
electrical failure for critical and essential loads in the facility. Data centers use generators 
to provide backup power for the entire facility.

AWS Partner Package – US State and Local Government and Education
 
Use or disclosure of data contained on this sheet is subject to the restriction on the title page of this document 
Q2 2023 
24 
 
• 
Climate and Temperature: Climate control is required to maintain a constant operating 
temperature for servers and other hardware, which prevents overheating and reduces 
the possibility of service outages. Data centers are conditioned to maintain atmospheric 
conditions at optimal levels. Personnel and systems monitor and control temperature 
and humidity at appropriate levels. 
• 
Physical Plant Management: AWS monitors electrical, mechanical, and life support 
systems and equipment so that any issues are immediately identified. Preventative 
maintenance is performed to maintain the continued operability of equipment. 
• 
Storage Device Decommissioning: As part of AWS’s storage decommissioning 
process, when a storage device has reached the end of its useful life, AWS procedures 
include a decommissioning process that is designed to prevent customer data from 
being exposed to unauthorized individuals. AWS uses the techniques detailed in 
National Institute of Standards and Technology (NIST) 800-88 (Guidelines for Media 
Sanitization) as part of the decommissioning process. 
AWS will provide the SOC 1 Type 2 report to customers under NDA. The AWS Security Center 
provides up-to-date information on AWS audits by independent third-party auditors. 
7. Automatic Scaling of Cloud Resources 
You can find more information in RFx Aid – Scalability and Elasticity.  
To help customers feel confident that infrastructure can handle a spike in traffic, they can use 
AWS Auto Scaling and Elastic Load Balancing to automatically scale their AWS cloud-based 
resources up to meet unexpected demand, and then scale those resources down as demand 
decreases. While AWS Auto Scaling adjusts capacity for multiple resources, Elastic Load 
Balancing distributes incoming application traffic across targets such as Amazon EC2 instances 
and containers. 
7.1. Scaling 
AWS Auto Scaling monitors customers’ applications and automatically adjusts capacity to 
maintain steady, predictable performance at the lowest possible cost. The service provides a 
user interface that lets customers build scaling plans for resources including Amazon EC2 
instances and Spot Fleets, Amazon ECS tasks, Amazon DynamoDB tables and indexes, and 
Amazon Aurora Replicas.  
Auto Scaling maintains the number of instances that the customers specifies by performing 
periodic health checks on the instances in the group. If an instance becomes unhealthy, the 
group terminates the unhealthy instance and launches another instance to replace it. 
Auto Scaling policies can be used to automatically increase or decrease the number of running 
Amazon EC2 instances in a group of servers to meet changing conditions. When the scaling 
policy is in effect, the Auto Scaling group adjusts the desired capacity of the group and launches 
or terminates the instances as needed, either dynamically or on a schedule if there is a known 
and predictable ebb and flow of traffic. 
7.2. Load Balancing 
Elastic Load Balancing automatically distributes incoming application traffic across multiple 
targets, such as Amazon EC2 instances, containers, IP addresses, and AWS Lambda functions. 
It can handle the varying load of application traffic in a single Availability Zone or across multiple 
Availability Zones. When combined with Auto Scaling, the number of healthy nodes is

AWS Partner Package – US State and Local Government and Education
 
Use or disclosure of data contained on this sheet is subject to the restriction on the title page of this document 
Q2 2023 
25 
 
automatically rebalanced with the other Availability Zones, and no manual intervention is 
required.  
Elastic Load Balancing offers three types of load balancers that all feature the high availability, 
automatic scaling, and robust security necessary to make applications fault tolerant: 
• 
Application Load Balancer: Best suited for load balancing of HTTP and HTTPS traffic 
• 
Network Load Balancer: Best suited for load balancing of Transmission Control 
Protocol (TCP) traffic where extreme performance is required 
• 
Classic Load Balancer: Best suited for applications that were built within the Amazon 
EC2-Classic network 
• 
Gateway Load Balancer: Best suited for deploying and running of third-party virtual 
appliances. 
7.3. Monitoring and Alarms 
Customers can use Amazon CloudWatch to collect and track metrics, collect and monitor log 
files, and set alarms. Customers can architect their solutions so that Amazon CloudWatch’s 
metrics and alarms can work together with Auto Scaling and Elastic Load Balancing to 
dynamically deploy new instances on-demand, as depicted in Figure 6. This type of automation 
reduces the administrative burden of the customer because the infrastructure instantaneously 
changes capacity to meet demand without active management. 
 
Figure 6: Auto Scaling and Elastic Load Balancing with Amazon CloudWatch alarms. Automatic 
scaling helps account for changes in capacity needs and user demand.  
8. Architecting for High Availability and Reliability  
You can find more information in RFx Aid – Reliability Resilience and Availability. 
Availability and reliability are shared responsibilities between AWS and the customer or AWS 
partner. AWS is responsible for ensuring that our services are continuously available and that

AWS Partner Package – US State and Local Government and Education
 
Use or disclosure of data contained on this sheet is subject to the restriction on the title page of this document 
Q2 2023 
26 
 
we are prepared to handle a wide range of events that could affect our infrastructure. 
Customers or AWS Partners are responsible for designing, deploying, and testing their 
applications on AWS to achieve the availability and resiliency they need, including for mission-
critical applications that require almost no downtime. The following subsections further detail 
AWS and customer responsibilities for availability and reliability. 
8.1. AWS Responsibility: Data Center Availability and Reliability 
AWS builds to guard against outages and incidents, and we account for them in the design of 
our services—so when disruptions do occur, their impact on customers and the continuity of 
services is as minimal as possible.  
To minimize disruptions, AWS employs compartmentalization. We have multiple constructs that 
provide different levels of independent, redundant components. For example, our Regions are 
isolated from each other, meaning that a disruption in one Region does not result in disruption in 
other Regions. Our Availability Zones are physically separated and isolated, and they are built 
with highly redundant networking to withstand local disruptions. AWS also leverages a concept 
known as cell-based architecture, by which resources and requests are partitioned into “cells” 
that are designed to be independent of each other. This design minimizes the chance that a 
disruption in one cell—for example, one subset of customers—would disrupt other cells.  
Additionally, although the likelihood of large-scale incidents is very low, AWS is prepared to 
manage them should they occur. We maintain a series of incident response plans covering both 
common and uncommon events, and we update them regularly to incorporate lessons learned 
and prepare for emerging threats.  
8.2. Customer Responsibility: Designing for Availability and Reliability 
While AWS goes to great lengths to provide availability and reliability of the cloud, our 
customers share responsibility for ensuring availability and reliability within the cloud. Some best 
practices we recommend for building highly resilient systems on the AWS Cloud include the 
following: 
• 
Design for Failure: It is best practice to architect across multiple AZs in the same 
Region to achieve extremely high Recovery Time Objectives (RTOs), Recovery Point 
Objectives (RPOs), and service availability. For mission-critical applications, it is best 
practice to architect across Regions to handle the rare case of an entire Region failing—
perhaps as a result of a major physical attack. 
• 
Automate Failover and Recovery: Customers can use AWS Auto Scaling to monitor 
their applications and automatically adjust capacity to maintain the optimal level to 
satisfy demand without over- or under-provisioning. Customers can also use AWS 
Personal Health Dashboard, which provides alerts and remediation guidance when AWS 
is experiencing events that may impact them. AWS Personal Health Dashboard can 
integrate with Amazon CloudWatch Events, allowing customers to build custom rules 
and select targets such as AWS Lambda functions to define automated remediation 
actions. 
• 
Test Recovery Procedures: Customers can use a test environment to simulate 
different failures or to recreate scenarios that led to failures before they occur. This 
exposes failure pathways that customers can test and fix before a real failure scenario, 
reducing the risk of components that have not been tested before failing.

AWS Partner Package – US State and Local Government and Education
 
Use or disclosure of data contained on this sheet is subject to the restriction on the title page of this document 
Q2 2023 
27 
 
8.3. Resources and Reference Architecture 
The AWS Well-Architected Framework codifies the experiences of thousands of customers, 
helping customers assess and improve their cloud-based architectures and mitigate disruptions. 
Our Reliability Pillar whitepaper provides guidance to help apply best practices to achieve 
reliability. 
In addition, the AWS Architecture Center provides customers with the necessary guidance and 
application architecture best practices to build highly scalable and reliable applications in the 
AWS Cloud. Figure 7 provides a reference architecture for fault tolerance and high availability. 
 
Figure 7: Fault Tolerant AWS Reference Architecture 
8.4. Building Secure Solutions on AWS 
You can find more information in RFx Aid – Security and AWS Security Best Practices,

AWS Partner Package – US State and Local Government and Education
 
Use or disclosure of data contained on this sheet is subject to the restriction on the title page of this document 
Q2 2023 
28 
 
AWS manages over a thousand security controls to provide a secure environment for our 
customers. The AWS virtual infrastructure is designed to provide optimum availability while 
ensuring customer security, privacy, and segregation. AWS’s highly secure data centers use 
state-of-the-art electronic surveillance and multi-factor access control systems and maintain 
strict, least-privileged-based access authorizations. Our environmental systems are designed to 
minimize the impact of disruptions to operations, and our multiple Regions and Availability 
Zones allow customers to remain resilient in the face of most failure modes.  
Remember that security is a shared responsibility between AWS and the AWS 
Partner/customer. While AWS is responsible for protecting the infrastructure that runs all of the 
services offered in the AWS Cloud, AWS Partners/customers control how they architect and 
secure their applications and data on the AWS Cloud. In addition, AWS provides security 
documentation that shows how to configure AWS services to meet security and compliance 
objectives. 
The following subsections provide further information on some of our most-inquired-about 
aspects of security. More information about security and responsibilities is available on our AWS 
Cloud Security and AWS Security Documentation webpages. 
8.5. Granting and Managing Account Access 
You can find more information in the RFx Aid – Access Control. 
Identity and access management are key parts of an information security program, ensuring that 
only authorized and authenticated users are able to access customers’ resources, and only in a 
manner that customers intend. Using AWS Identity and Access Management (IAM), customers 
can create and manage AWS users and groups, assign them security credentials (e.g., access 
keys, passwords, and multi-factor authentication [MFA] devices), and use permissions to allow 
and deny their access to AWS resources. Customers can also request temporary security 
credentials for users who only require short-term access. 
8.5.1. IAM Users 
An IAM user is an entity that the customer creates in AWS. The IAM user represents the person or 
service who uses the IAM user to interact with AWS. A user in AWS consists of a name, a password 
to sign into the AWS Management Console, and up to two access keys that can be used with the API 
or CLI.  
When the customer creates an IAM user, they grant it permissions either by making it a member 
of a group that has appropriate permission policies attached (recommended) or by directly 
attaching policies to the user. The customer can also clone the permissions of an existing IAM 
user, which automatically makes the new user a member of the same groups and attaches all 
the same policies.  
A root user is a single sign-in identity that has complete access to all AWS Cloud services and 
resources in the account. It is a security best practice to not use the root account because of its 
complete access. Instead, create individual users and grant them each the minimum amount of 
privilege necessary, which is known as least privilege. Note that all users have zero privileges 
by default. Customers can manage users’ privilege by individual user or by groups.  
8.5.2. IAM Groups 
An IAM user group is a collection of IAM users. Customers can use groups to specify 
permissions for a collection of users, which can make those permissions easier to manage for 
those users. For example, a customer could have a group called Admins and give that group

AWS Partner Package – US State and Local Government and Education
 
Use or disclosure of data contained on this sheet is subject to the restriction on the title page of this document 
Q2 2023 
29 
 
the types of permissions that administrators typically need. Any user in that group automatically 
has the permissions that are assigned to the group. Note that a group is not truly an identity 
because it cannot be identified as a Principal in a resource-based or trust policy. It is only a way 
to attach policies to multiple users at one time. 
8.5.3. IAM Roles 
An IAM role is very similar to a user, in that it is an identity with permission policies that 
determine what the identity can and cannot do in AWS. However, a role does not have any 
credentials (password or access keys) associated with it. Instead of being uniquely associated 
with one person, a role is intended to be assumable by anyone who needs it. An IAM user can 
assume a role to temporarily take on different permissions for a specific task. A role can be 
assigned to a federated user who signs in by using an external identity provider instead of IAM. 
AWS uses details passed by the identity provider to determine which role is mapped to the 
federated user. 
8.5.4. Identity Federation 
With Identity Federation, customers can use single sign-on (SSO) to access their AWS 
accounts using credentials from their corporate directory. Federation uses open standards such 
as Security Assertion Markup Language 2.0 (SAML) to exchange identity and security 
information between an identity provider and an application. 
8.5.5. Setting Granular Permissions 
Access control policies are attached to users, groups, and roles to assign permissions to AWS 
resources. By default, IAM users, groups, and roles have no permissions; users with sufficient 
permissions must use a policy to grant the desired permissions. 
Using policies, customers can specify several layers of permission granularity. First, customers 
can define specific AWS service actions they wish to allow or explicitly deny access to. Second, 
depending on the action, they can define specific AWS resources upon which the actions can 
be performed. Third, customers can define conditions to specify when the policy is in effect (for 
example, if MFA is enabled or not). 
8.5.6. Temporary Security Credentials  
Customers can use the AWS Security Token Service (AWS STS) to create and provide trusted 
users with temporary security credentials that can control access to their AWS resources. 
Temporary security credentials are short-term and are not stored with the user; rather, they are 
generated dynamically and provided to the user when requested.  
8.6. Tools for Logical Separation 
AWS Cloud services and features that provide logical separation are enough to meet most 
security requirements, despite legacy requirements for physical separation. Amazon VPC, for 
example, allows customers to define and provision their own logically isolated section of the 
AWS Cloud. Amazon VPC provides a networking layer for Amazon EC2, a service that provides 
compute capacity within the AWS Cloud. Each Amazon VPC is logically separated from other 
virtual networks on the AWS Cloud, and it allows customers to launch their resources into an IP 
address range that they determine. 
Within a VPC, customers can create subnets, each with an associated route table. They can 
configure these route tables to control network traffic. Customers can attach an internet gateway

AWS Partner Package – US State and Local Government and Education
 
Use or disclosure of data contained on this sheet is subject to the restriction on the title page of this document 
Q2 2023 
30 
 
to their VPC, allowing their Amazon EC2 instances to communicate with the public internet. 
Customers can also create private subnets that only allow their Amazon EC2 instances to 
communicate with each other. Our Amazon VPC User Guide provides several example 
scenarios for building both public and private subnets. 
In addition, AWS offers services like VPC Peering, AWS Transit Gateway, and AWS 
PrivateLink, which allow VPCs to communicate with each other and with other services on the 
AWS Cloud both securely and privately. 
8.7. Tools for Encryption 
All AWS Cloud services that store customer data offer the ability to encrypt that data. By 
defining an encryption approach, customers can provide protection for their content against 
unauthorized users and against unnecessary exposure to authorized users. The combination of 
AWS Key Management Service (KMS) and AWS CloudHSM is the centerpiece of a rigorous 
encryption solution.  
AWS KMS helps customers manage encryption keys and integrates with many AWS Cloud 
services. This service provides durable, secure, and redundant storage for customers’ master 
keys. Customers can define their key aliases as well as key-level policies. The policies help 
define key administrators as well as key users. For example, a secret management system can 
be the only system that has access to the master key that encrypts the secrets for storage.  
AWS CloudHSM is a cloud-based hardware security module (HSM) that allows customers to 
easily generate and use their own encryption keys on the AWS Cloud. It helps customers meet 
corporate, contractual, and regulatory compliance requirements for data security by using 
Federal Information Processing Standard (FIPS) 140-2 Level 3 validated HSMs. 
8.7.1. Protecting Data at Rest 
Multiple AWS Cloud services provide built-in integration with AWS KMS to allow easy 
encryption of data. Amazon S3 allows customers to encrypt content by selecting a KMS key on 
object upload. Amazon EBS allows customers to choose a KMS key to encrypt a block storage 
volume or Amazon Machine Image (AMI) copy operation. Amazon RDS allows customers to 
choose an encryption key for encrypting DB instance storage at rest (including backup 
snapshots). 
Customers also have the option of implementing their own encryption-at-rest approach. For 
example, they can encrypt content before storing in an AWS Cloud service. Amazon S3 
provides the facility to upload an already encrypted object. It also provides the ability to upload 
an object along with an encryption key that’s used in-memory to encrypt an object. To retrieve 
the object, the customer must supply the same key. 
8.7.2. Protecting Data in Transit 
When protecting data in transit, selecting secure protocols that implement the latest in 
cryptography standards such as Transport Layer Security (TLS) is a common best practice. 
AWS Cloud services provide HTTPS endpoints using TLS for communication, thus providing 
encryption in transit when communicating with the AWS APIs. The customer has full control 
over their computing resources to implement encryption in transit across their services. 
Additionally, the AWS Certificate Manager (ACM) service allows customers to manage and 
deploy public and private certificates for their workloads. They can also leverage virtual private 
network (VPN) connectivity into their VPC or across VPCs to facilitate encryption of traffic.

AWS Partner Package – US State and Local Government and Education
 
Use or disclosure of data contained on this sheet is subject to the restriction on the title page of this document 
Q2 2023 
31 
 
8.8. Automating Security and Compliance 
AWS offers a variety of security tools that customers can use to secure the applications they build 
on the AWS Cloud. These includes AWS CloudTrail and AWS CloudWatch for logging and 
monitoring, Amazon GuardDuty for threat detection, and AWS Shield for DDoS protection. Our 
Security, Identity, and Compliance on AWS page provides a more complete listing and details on 
the myriad services we offer. Customers can use these tools—and the tools of our AWS 
Partners—to automate security. 
8.9. Penetration Testing 
AWS customers are responsible for all scanning, penetration testing, file integrity monitoring, 
and intrusion detection for their Amazon EC2 instances, Amazon RDS databases, and various 
other applications. (Refer to the Penetration Testing page for terms of service regarding 
penetration testing.) Penetration tests should include customer IP addresses and not AWS 
endpoints. AWS endpoints are tested as part of AWS compliance vulnerability scans.  
8.10. Data Breaches 
Both AWS and customers (and any AWS Partners they engage) have responsibilities to 
respond to a data breach. AWS customers and AWS Partners retain the responsibility to 
monitor their own environment for privacy breaches. The AWS SOC reports provide an 
overview of the controls that are in place to monitor the AWS managed environment. 
We recommend that customers and AWS Partners consider implementing the following best 
practices to protect against and detect security breaches: 
• 
Use encryption to secure data. 
• 
Configure AWS Cloud services to keep data secure. AWS provides information on how 
to secure resources in our security documentation. 
• 
Implement least privilege permissions for access to resources and data. 
• 
Use monitoring tools like Amazon CloudWatch to track when data is accessed and by 
whom. 
• 
Review AWS’s Best Practices for Security, Identity, and Compliance page for additional 
information on how to protect against and detect security breaches. 
AWS Partners and customers are responsible for reporting incidents involving customer 
storage, virtual machines, and applications (for more information, refer to our Vulnerability 
Reporting page). AWS maintains the AWS Security Bulletins webpage to notify customers of 
security and privacy events affecting AWS Cloud services. Customers can subscribe to the 
Security Bulletin RSS Feed to keep abreast of security announcements on the Security Bulletin 
webpage. The customer support team maintains a Service Health Dashboard webpage to alert 
customers to any broadly impacting availability issues. 
9. AWS Training and Certification 
You can find more information in RFx Aid – AWS Training and Development.  
AWS recommends that AWS Partners incorporate cloud training into migration or significant 
cloud initiatives. Industry studies show that comprehensively trained customers are more 
successful relative to their peers in implementing cloud, so we provide guidance below that 
AWS Partners can use when they are seeking to train government customers.

AWS Partner Package – US State and Local Government and Education
 
Use or disclosure of data contained on this sheet is subject to the restriction on the title page of this document 
Q2 2023 
32 
 
9.1. Benefits of Training and Certification 
AWS Training & Certification offers the cloud skills enablement resources that government 
entities need to modernize their agencies; create a culture of innovation; and attract, develop, 
and retain cloud talent. AWS works closely with AWS Partners to develop a workforce 
development plan to build cloud computing capabilities based on training needs. Leveraging 
AWS Training and Certification for organizational training can help accomplish the following: 
• 
Achieve Cloud Adoption Goals Sooner: Organizations with comprehensive training 
adopt cloud technology faster than those who do not take advantage of a 
comprehensive training program. This helps move projects forward, get to market faster, 
drive revenue, and capitalize on the cost savings associated with AWS. 
• 
Gain Stakeholder Buy-In: AWS Training will help orient and familiarze teams with cloud 
initiatives. The Train to Accelerate Your Cloud Strategy whitepaper presented by the 
International Data Corporation (IDC) found that comprehensively-trained organizations 
were 4.4 times more likely to overcome operational and performance concerns. This 
means less time spent on stakeholder alignment and more time spent on innovation and 
business growth. 
• 
Improve Employee Productivity: The IDC’s whitepaper also found that decision 
makers within comprehensively-trained organizations are 4.7 times more likely to agree 
that cloud technology can improve IT staff productivity. AWS Training helps teams 
become more productive by using the cloud. 
9.2. Approach to Training and Workforce Development 
AWS is investing hundreds of millions of dollars to provide free cloud computing training to 29 
million people around the world by 20251.  AWS and its partners can provide a comprehensive 
curriculum to organizations that need foundational technology upskilling and cloud computing 
training.   
Our approach to workforce development typically begins in the classroom but must extend to 
solving real-world business and technology challenges. It constitutes a learning continuum 
across three building blocks: Learn, Explore, and Apply. Each phase can be customized to 
optimize the learning path for the specific organization’s growth. We illustrate each of these 
phases in Figure 8 below.  
                                               
1 See Amazon to help 29 million people around the world grow their tech skills with free cloud computing 
skills training by 2025

AWS Partner Package – US State and Local Government and Education
 
Use or disclosure of data contained on this sheet is subject to the restriction on the title page of this document 
Q2 2023 
33 
 
 
Figure 8: Phases of Learning Continuum 
• 
Learn: Focuses on traditional classroom (or virtual training) that educates students how 
to build on, secure, operate, and manage AWS services, supplemented by self-paced 
and on-demand digital training that can be consumed at any time. 
• 
Explore: Tailors learning opportunities to the agency’s environment and builds on base 
knowledge and skills though targeted and more focused interactive learning modalities.   
• 
Apply: Dives into building proofs of concept (POCs) and solutions that solve agency-
specific business and technology challenges.      
9.3. Learning Needs Analysis 
For customers with significant training needs for end-customers, AWS Partners can work with 
an AWS Training Lead to conduct a Learning Needs Analysis as described below.  
AWS Training and Certification offers a no-cost self-assessment survey known as the Learning 
Needs Analysis (LNA). The LNA helps identify AWS skill gaps and recommends organizational 
and individual training plans to address these gaps. The LNA helps optimize training 
investments and acquire critical skills more quickly. This can be especially useful for scenarios 
involving large customers who can have large numbers of employees participate. 
The LNA is a two-step process:  
1. Complete the self-assessment survey: Individuals in the organization complete a 
self-assessment, which measures cloud knowledge and skill across multiple 
functional areas. The survey takes approximately 10 minutes to complete. 
2. Review skills gaps and training plans: AWS identifies skill gaps and generates 
training plans based on survey results. 
Once organizations complete the LNA, AWS Training Experts, Specialists, and Solution 
Architects can customize training, workshops, and deep dives specialized for their industry. We 
then support delivery of our customized offerings both digitally and onsite.

AWS Partner Package – US State and Local Government and Education
 
Use or disclosure of data contained on this sheet is subject to the restriction on the title page of this document 
Q2 2023 
34 
 
9.4. Modes of Training Delivery 
We offer free digital training, in-depth classroom training, private onsite training, and select 
learning events. Training options include the following: 
• 
Free Digital Training: Over 500 on-demand digital courses that help customers and AWS 
Partners learn new cloud skills and services when and where it is convenient for them, at 
no cost. For example, customers and partners can get free hands-on training with AWS 
hosted on qwikLABS.com. 
• 
AWS Skill Builder: On-demand digital courses that are self-paced to help learners build 
new cloud skills.  
• 
AWS Training Partner (ATP) Courses: Self-paced digital or classroom courses covering 
a range of topics, influding fundamental and advnaced AWS Cloud topics, all provided 
by top AWS Training Partners, including edX and Coursera.  
• 
Classroom Training: Live classes delivered virtually or in person by accredited AWS 
instructors who teach in-demand cloud skills and best practices using a mix of 
presentations, discussion, and hands-on labs. 
• 
Private Onsite Training: Virtual or in-person classes with accredited AWS instructors 
who teach in-depth AWS Cloud skills in a private environment that brings the classroom 
to learners. 
• 
Events: Register for online or in-person events to learn how to leverage the power of the 
AWS Cloud. 
Table 2 illustrates features of AWS Training and Certification delivery.

AWS Partner Package – US State and Local Government and Education
 
Use or disclosure of data contained on this sheet is subject to the restriction on the title page of this document 
Q2 2023 
37 
 
10.1. Certifications and Attestations 
Certifications and attestations are performed by a third-party independent auditor. Our 
certifications, audit reports, and attestations of compliance are based on the results of the 
auditor’s work. AWS offers its customers comprehensive compliance controls, and supports 
more security standards and compliance certifications than any other offering. We help 
customers satisfy compliance requirements for virtually every regulatory agency around the 
globe, including PCI-DSS, HIPAA/HITECH, FedRAMP, GDPR, FIPS 140-2, and NIST 800-171.   
A list of the most frequently requested certifications in the US state, local, and education market 
includes:  
• 
Federal Risk and Authorization Management Program (FedRAMP), 
• 
Federal Information Processing Standard (FIPS), 
• 
International Organization for Standardization (ISO) 9001:2015, 
• 
ISO/International Electrotechnical Comission (IEC) 27001:2013, 
• 
ISO/IEC 27018:2019, 
• 
Payment Card Industry Data Security Standard (PCI DSS), 
• 
System and Organization Control (SOC) Reports. 
For more information about these certifications, see Appendix C. The full list of certifications and 
attestations can be found at https://aws.amazon.com/compliance/. 
10.2. Laws, Regulations, and Privacy 
AWS customers remain responsible for following applicable compliance laws and regulations. In 
some cases, AWS offers functionality (such as security features), enablers, and legal 
agreements (such as the AWS Data Processing Agreement and Business Associate 
Addendum) to support customer compliance. No formal certification is available to (or 
distributable by) a CSP like AWS within these law and regulatory domains. The following 
subsections provide details on the laws, regulations, and privacy considerations that AWS 
Partners ask about most often. These include:  
• 
Family Educational Rights and Privacy Act (FERPA) 
• 
Health Insurance Portability and Accountability Act of 1996 (HIPAA)/ Health Information 
Technology for Economic and Clinical Health (HITECH) 
• 
Internal Revenue Service Publication 1075 (IRS Pub 1075) 
• 
Voluntary Product Accessibility Template (VPAT)/Section 508 
10.2.1. FERPA  
The Family Educational Rights and Privacy Act (FERPA) of 1974 was enacted to support and 
promote the protection of privacy and reasonable governance of student education records. 
FERPA provides parents of students and eligible students with the following:  
• 
The right to inspect and review their education records 
• 
Governance over disclosure of their education records 
• 
A mechanism to amend incorrect education records 
FERPA requires states to use reasonable methods to ensure the security of their IT solutions. 
This may be achieved by hosting education records on cloud computing solutions. The law, in 
general, requires covered institutions and agencies to reasonably safeguard student education

AWS Partner Package – US State and Local Government and Education
 
Use or disclosure of data contained on this sheet is subject to the restriction on the title page of this document 
Q2 2023 
38 
 
records from improper use or disclosure. Securing student record information, including 
students’ personally identifiable information (PII), is essential for educational institutions and 
vendors that provide services which fall under the purview of FERPA.  
AWS and FERPA: AWS implements physical and logical controls for internal services and 
provides robust offerings externally for customers to leverage in order to comply with FERPA. 
These controls are discussed in detail in our FERPA Compliance on AWS whitepaper. 
FERPA for AWS Partners: Because FERPA was authored in 1974, it lacks clear guidance on 
modern technology use, which means that educational institutions are often left to create their 
own solutions. As part of this solution, customers are encouraged to take steps such as creating 
device compliance policies, threat protection plans, and data loss prevention plans that suit their 
organization to protect sensitive information. In addition, customers are encouraged to use 
encryption and access controls. Access controls also provide auditing and logging capabilities to 
customers in order to validate privacy and data protection policies that customers have in place. 
AWS offers a comprehensive set of features and services to make encryption of PII easy to 
manage and simpler to audit, including AWS KMS. Customers with FERPA compliance 
requirements have a great deal of flexibility in how they meet encryption requirements for PII. 
10.2.2. HIPAA/HITECH 
Health Insurance Portability and Accountability Act (HIPAA) legislation is designed to make it 
easier for US workers to retain health insurance coverage when they change or lose their jobs. 
This legislation also encourages electronic health records to improve the efficiency and quality 
of the US healthcare system through improved information sharing. Along with increasing the 
use of electronic medical records, HIPAA includes provisions to protect the security and privacy 
of protected health information (PHI). 
Health Information Technology for Economic and Clinical Health (HITECH) expanded the 
HIPAA rules in 2009. HIPAA and HITECH together establish a set of federal standards that are 
intended to protect the security and privacy of PHI. 
10.2.2.1. AWS and HIPAA 
There is no HIPAA certification for a CSP such as AWS. In order to meet the HIPAA 
requirements applicable to our operating model, AWS aligns our HIPAA risk management 
program with FedRAMP and NIST 800-53, which are higher security standards that map to the 
HIPAA Security Rule. NIST supports this alignment and has issued SP 800-66: An Introductory 
Resource Guide for Implementing the HIPAA Security Rule, which documents how NIST 800-53 
aligns to the HIPAA Security Rule. 
Under the HIPAA regulations, AWS is considered a business associate. The BAA is an AWS 
contract that is required under HIPAA rules to ensure that AWS appropriately safeguards PHI. 
The BAA also serves to clarify and limit, as appropriate, the permissible uses and disclosures of 
PHI by AWS, based on the relationship between AWS and our customers, and the activities or 
services being performed by AWS. 
AWS has a standard BAA we present to customers for signature. This BAA accounts for the 
unique services AWS provides and accommodates within the AWS Shared Responsibility 
Model. To review, accept, and manage the status of the BAA for a specific account, sign in 
to AWS Artifact. Note that some AWS Artifact documentation is available under NDA, and use 
of the content is subject to the terms of that NDA.

AWS Partner Package – US State and Local Government and Education
 
Use or disclosure of data contained on this sheet is subject to the restriction on the title page of this document 
Q2 2023 
39 
 
10.2.2.2. HIPAA for AWS Partners  
AWS helps covered entities and their business associates use the secure AWS environment to 
process, maintain, and store PHI. 
For detailed information about how to use AWS for the processing and storage of health 
information, see the whitepaper Architecting for HIPAA Security and Compliance on Amazon 
Web Services. 
10.2.3. IRS Pub 1075 
Internal Revenue Service Publication 1075 (IRS Pub 1075) provides guidance for US 
government agencies and their agents to protect Federal Tax Information (FTI). 
While the IRS does not publish an official designation or certification for compliance with IRS 
Pub 1075, AWS supports organizations to protect FTI managed on the AWS Cloud by aligning 
our implementations of NIST 800-53 and FedRAMP security controls with the respective IRS 
Pub 1075 security requirements. AWS has worked closely with the IRS to ensure that the AWS 
GovCloud (US) and AWS US East/West Regions meet Pub 1075 requirements for storing and 
processing FTI. Refer to Appendix C.1 for information on AWS and FedRAMP security controls. 
10.2.4. VPAT/Section 508 
In 1998, the US Congress amended the Rehabilitation Act of 1973 to require Federal agencies 
to make their electronic and information technology accessible to people with disabilities. 
Inaccessible technology interferes with an individual’s ability to obtain and use information 
quickly and easily. Section 508 was enacted to eliminate barriers in information technology (IT), 
make available new opportunities for people with disabilities, and encourage development of 
technologies that will help achieve these goals. 
The law applies to all Federal agencies when they develop, procure, maintain, or use electronic 
IT. Under Section 508 (29 U.S.C. § 794 (d)), agencies must give disabled employees and 
members of the public access to information that is comparable to the access available to 
others. Because Section 508 is a federal and state requirement, any and all of AWS 
government customers will have Section 508 compliance needs. 
10.2.4.1. AWS and VPAT/Section 508 
AWS provides multiple interfaces to its cloud computing services, including application 
programming interfaces (APIs), software development kits (SDKs), integrated development 
environment (IDE) toolkits, and command line tools. 
To address accessibility requirements, AWS offers the AWS Command Line Interface (AWS 
CLI), a unified tool that provides a consistent, text-based interface to interact with all parts of 
AWS. With just one tool, users can control services from the command line and automate them 
through scripts. The AWS CLI can be used by customers with a diverse range of needs, 
including those who use assistive technology such as Job Access with Speech (JAWS), 
Nonvisual Desktop Access (NVDA), and alternative input devices.  
An Accessibility Conformance Report (ACR) was performed for the AWS CLI by completing 
Voluntary Product Accessibility Template® (VPAT) Version 2.3 in March 2019. The ACR 
provides assessments against Section 508 requirements and Web Content Accessibility 
Guidelines (WCAG) 2.1 Level A and AA requirements. 
AWS also offer an alternative for users who prefer a graphical user interface. AWS ElasticWolf 
Client Console is a client-side application with an easy-to-use interface that is compatible with

AWS Partner Package – US State and Local Government and Education
 
Use or disclosure of data contained on this sheet is subject to the restriction on the title page of this document 
Q2 2023 
40 
 
assistive technologies such as JAWS, ZoomText, Orca, alternative input devices, and NVDA. 
Examples of its accessible design include semantically-marked up form field labels, visible and 
semantically-marked up button labels, and keyboard accessible content.  
AWS ElasticWolf Client Console integrates with the AWS CLI and can manage AWS resources 
in all AWS Regions. It provides access to many foundational and widely-used AWS services, 
including AWS CloudFormation, AWS Identity and Access Management (IAM), Amazon Elastic 
Compute Cloud (Amazon EC2), Amazon EMR, Amazon Relational Database Service (Amazon 
RDS), Amazon Route 53, Amazon Simple Queue Service (Amazon SQS), and Amazon Simple 
Storage Service (Amazon S3). 
An ACR was performed for AWS ElasticWolf Client Console by completing VPAT Version 2.3 in 
March 2020. The ACR, performed for both Windows and Linux versions, provides assessments 
against Section 508 requirements and WCAG 2.0 Level A and AA requirements. The ACR is 
available through AWS Artifact. 
10.3. Alignments/Frameworks 
Compliance alignments and frameworks include published security or compliance requirements 
for a specific purpose, such as a specific industry or function. AWS provides functionality (such 
as security features) and enablers (including compliance playbooks, mapping documents, and 
whitepapers) for these types of programs. 
Requirements under specific alignments and frameworks may not be subject to certification or 
attestation; however, some alignments and frameworks are covered by other compliance 
programs. The following subsections provide details on the alignments and frameworks that 
AWS Partners ask about most frequently. 
10.3.1. Criminal Justice Information Services 
Criminal Justice Information (CJI) refers to the data necessary for law enforcement agencies to 
perform their mission and enforce the laws, such as biometric, identity history, person, 
organization, property, and case/incident history data. CJI also refers to data necessary for civil 
agencies to perform their mission, including data used to make hiring decisions.  
The Criminal Justice Information Services (CJIS) Security Policy reflects the shared 
responsibility between Federal Bureau of Investigation (FBI) CJIS, CJIS Systems Agency, and 
the State Identification Bureaus (SIB) of the lawful use and appropriate protection of CJI. The 
CJIS Security Policy provides a baseline of security requirements for current and planned 
services and establishes a minimum standard for new initiatives. 
10.3.1.1. AWS and CJIS 
By using solutions built on AWS, agencies can manage and secure their applications, data, and 
other CJIS resources in the AWS GovCloud (US). AWS GovCloud (US) Regions consist of US 
data centers hosting services authorized to FedRAMP High, managed by US citizens, and 
offering the FIPS validated endpoints necessary to build CJIS-compliant solutions. 
Technological advancements have removed the need to engage in the traditional method of 
relying on physical security and background checks as a way to qualify an individual’s “access” 
to unencrypted CJI. While the traditional approach can help achieve minimum compliance under 
the CJIS Security Policy, it doesn’t compare to the security that can be achieved using strong 
encryption practices and the deployment of “least privilege” principles to restrict CJI access to 
those with a need-to-know, right-to-know, and explicit authorization.

AWS Partner Package – US State and Local Government and Education
 
Use or disclosure of data contained on this sheet is subject to the restriction on the title page of this document 
Q2 2023 
41 
 
10.3.1.2. CJIS for AWS Partners 
Properly securing CJI and maintaining compliance with the CJIS Security Policy requires a 
number of security controls aimed at ensuring only authorized individuals have access to the 
CJI. 
One critical control is the use of independently tested and validated encryption to protect 
sensitive information both in-transit and at-rest, regardless of physical location. AWS empowers 
customers and partners to encrypt their criminal justice data in AWS GovCloud (US) employing 
FIPS 140-2 validated encryption in-transit services and FIPS-197 compliant encryption for data 
at-rest. AWS GovCloud (US) also offers AWS Key Management Service (AWS KMS) using 
FIPS 140-2 validated hardware security modules, allowing customers to create, own, and 
manage their own customer master keys for all encryption. These customer master keys never 
leave the AWS KMS FIPS validated hardware security modules unencrypted and are never 
known to AWS personnel. 
Another critical control involves limiting access to individuals who hold or manage encryption 
keys, allowing agencies to define and limit the universe of users with logical access to CJI. The 
principal of least privilege is one of the most fundamental underpinnings of the CJIS Security 
Policy based on a “need-to-know, right-to-know” standard. AWS GovCloud (US) customers can 
enforce least privilege by securely encrypting their CJI and limiting all access to the CJI to only 
those with access to the encryption keys. By using AWS GovCloud (US), customers are 
provided AWS Cloud services, tools, and security assurance to enable them to retain complete 
control and ownership over their own criminal justice data. 
See our webpage, Using AWS for Criminal Justice Information Solutions, for additional 
information. 
10.3.2. Cloud Security Alliance 
Cloud Security Alliance (CSA) is a not-for-profit organization that aims to promote security 
assurance within cloud computing using reliable and recommended processes and practices, 
and to educate on the uses of cloud computing to help secure all other forms of computing. 
10.3.2.1. AWS and CSA 
AWS participates in the voluntary CSA Security, Trust & Assurance Registry (STAR) Self-
Assessment to document our compliance with CSA-published best practices. We publish our 
completed CSA Consensus Assessments Initiative Questionnaire (CAIQ) on the AWS website. 
10.3.2.2. CSA for AWS Partners 
The CSA CAIQ provides a set of questions that the CSA anticipates a cloud consumer and/or 
cloud auditor would ask of a CSP like AWS. It provides a series of security, control, and process 
questions that can then be used for a wide range of uses, including cloud provider security 
evaluation.  
10.3.3. Federal Information Security Management Act  
AWS enables US government agencies to achieve and sustain compliance with the Federal 
Information Security Management Act (FISMA). AWS’s infrastructure has been evaluated by 
independent assessors for a variety of government systems as part of their system owners’ 
approval process. Numerous Federal Civilian and DoD organizations have successfully 
achieved security authorizations for systems hosted on AWS in accordance with the Risk 
Management Framework (RMF) process defined in NIST 800-37 and DoD Information

AWS Partner Package – US State and Local Government and Education
 
Use or disclosure of data contained on this sheet is subject to the restriction on the title page of this document 
Q2 2023 
42 
 
Assurance Certification and Accreditation Process (DIACAP). AWS’s secure infrastructure has 
helped federal agencies expand cloud computing use cases and deploy sensitive government 
data and applications in the cloud while complying with the rigorous security requirements of 
federal standards. 
10.3.4. National Institute of Standards and Technology 800-53 
National Institute of Standards and Technology (NIST) 800-53 security controls are generally 
applicable to US Federal Information Systems. Federal Information Systems typically must go 
through a formal assessment and authorization process to ensure sufficient protection of 
confidentiality, integrity, and availability of information and information systems. 
The NIST Cybersecurity Framework (CSF) is supported by governments and industries 
worldwide as a recommended baseline for use by any organization, regardless of its sector or 
size. Since Fiscal Year 2016, federal agency FISMA metrics have been organized around the 
CSF, and agencies are now required to implement the CSF under the Cybersecurity Executive 
Order. 
10.3.4.1. AWS and NIST 800-53 
AWS Cloud infrastructure and services have been validated by third-party testing performed 
against the NIST 800-53 Revision 4 controls and additional FedRAMP requirements. AWS has 
received FedRAMP ATOs from multiple authorizing agencies for both AWS GovCloud (US) and 
the AWS US East/West Regions. For more information, see the AWS FedRAMP 
compliance webpage, or the following FedRAMP Marketplace webpages: 
• 
AWS East/West Region complete list of authorizing agencies 
• 
AWS GovCloud (US) complete list of authorizing agencies 
• 
AWS GovCloud JAB P-ATO at the high baseline 
10.3.4.2. NIST 800-53 for AWS Partners 
Under NDA, AWS provides an AWS FedRAMP SSP template based upon NIST 800-53 Rev. 4, 
which is prepopulated with the applicable NIST 800-5 Rev. 4 Low/Moderate/High control 
baseline. Control responsibility is as follows: 
• 
Shared Responsibility: The customer will provide security and configurations of their 
software components, and AWS will provide security for its infrastructure. 
• 
Customer-Only Responsibility: The customer is fully responsible for guest operating 
systems, deployed applications, and select networking resources (for example, 
firewalls). More specifically, the customer is solely responsible for configuring and 
managing security in the cloud. 
• 
AWS-Only Responsibility: AWS manages the cloud infrastructure, including the 
network, data storage, system resources, data centers, physical security, reliability, and 
supporting hardware and software. Applications built on top of the AWS system inherit 
the features and configurable options that AWS provides. AWS is solely responsible for 
configuring and managing security of the cloud. 
For security authorization purposes, compliance with the FedRAMP requirements (based on 
NIST 800-53 rev 4 Low/Moderate/High control baseline) is contingent upon AWS fully 
implementing AWS-only and shared controls and the customer or AWS Partner implementing 
customer-only and shared controls. A FedRAMP-accredited 3PAO has assessed and 
authorized AWS implementation of our control responsibility. The portion of shared controls that 
the customer or AWS Partner is responsible for and the controls related to applications they

AWS Partner Package – US State and Local Government and Education
 
Use or disclosure of data contained on this sheet is subject to the restriction on the title page of this document 
Q2 2023 
43 
 
implement on top of the AWS infrastructure must be separately assessed and authorized by 
them in agreement with NIST 800-37 and their specific security authorization policies and 
procedures. 
AWS FedRAMP-compliant systems have been granted authorizations, have addressed the 
FedRAMP security controls (NIST 800-53), use the required FedRAMP templates for the 
security packages posted in the secure FedRAMP Repository, have been assessed by an 
accredited independent 3PAO, and maintain the continuous monitoring requirements of 
FedRAMP. 
Customers and AWS Partners can use our NIST CSF whitepaper to assess their AWS 
environment against the NIST CSF and improve the security measures they implement and 
operate. The whitepaper also provides a third-party auditor letter attesting to the AWS Cloud 
services’ conformance to NIST CSF risk management practices. 
10.3.5. Uptime Institute Tiers 
The Uptime Institute created the standard Tier Classification System to evaluate various data 
center facilities in terms of potential site infrastructure performance, or uptime. Uptime Institute 
has not authorized other organizations to certify data centers under its Tier Classification 
System. Uptime Institute does not design, build, or operate data centers. 
10.3.5.1. AWS and Uptime Institute Tiers 
AWS operates our data centers in alignment with the Tier III+ guidelines, but we have chosen 
not to have a certified Uptime Institute-based tiering level so that we have more flexibility to 
expand and improve performance. AWS’s approach to infrastructure performance 
acknowledges Uptime Institute’s tiering guidelines and applies them to our global data center 
infrastructure design to ensure the highest level of performance and availability for our 
customers. AWS then improves on the guidelines provided by the Uptime Institute to scale for 
global operations and produce an operating outcome for availability and performance that far 
exceeds that which would be achieved through the Uptime Institute tiering guidelines alone. 
Although we do not claim alignment with Tier IV, we can ensure that our systems have a fault 
tolerant sequence of operations with self-correcting mitigations in place. 
AWS has identified critical system components required to maintain the availability of the 
system and recover service in the event of outage. Critical system components are backed up 
across multiple, isolated locations known as Availability Zones. Each Availability Zone runs on 
its own physically distinct, independent infrastructure, and is engineered to be highly reliable. 
Availability Zones are connected to each other with fast, private fiber-optic networking, enabling 
customers and AWS Partners to easily architect applications that automatically fail-over 
between Availability Zones without interruption. 
10.3.5.2. Uptime Institute Tiers for AWS Partners 
AWS customers can build highly resilient systems in the cloud by employing multiple instances 
in multiple Availability Zones plus data replication to achieve extremely high recovery time and 
recovery point objectives, as well as service availability of 99.999% and more. Service 
availability is therefore a function of the design; customers who care about the availability and 
performance of their applications want to deploy these applications across multiple Availability 
Zones in the same region for fault tolerance and low latency. Some AWS Cloud services, such 
as Amazon S3, are built to leverage all Availability Zones within the region and have a durability 
objective of 99.999999999%.

AWS Partner Package – US State and Local Government and Education
 
Use or disclosure of data contained on this sheet is subject to the restriction on the title page of this document 
Q2 2023 
44 
 
11. Managing AWS Resources  
You can find more information in RFx Aid – Managing your AWS Resources. 
With the AWS Cloud, customers can easily provision, manage, and monitor all of their IT 
resources in one location with the tool that best fits their unique needs. This helps them know 
what is going on in their cloud environment, such as instance health, logs of user actions, and 
ways to save money. AWS Cloud services are driven by robust APIs that allow for a wide 
variety of monitoring, management and developer tools to integrate easily with AWS Cloud 
resources. AWS supports common tools from vendors such as Microsoft, VMware, BMC 
Software, Okta, RightScale, Eucalyptus, CA, Xceedium, Symantec, Racemi, and Dell. Below 
are some AWS-native management options, which can be used alongside familiar management 
tools available on AWS Marketplace.  
11.1. AWS Management Console 
The AWS Management Console is a single destination for managing all AWS resources. 
Customers can use the AWS Management Console to perform any number of tasks (e.g., 
deploying new applications, monitoring the health of applications, accessing monthly spending 
by service, and managing security credentials). The AWS Management Console supports all 
AWS Regions and lets customers provision resources across multiple Regions. 
11.2. Command Line Interface (CLI) 
The AWS CLI is a unified tool used to manage AWS Cloud services. With just one tool to 
download and configure, customers can control multiple AWS resources from the command line 
and automate them through scripts. The AWS CLI introduces a new set of simple file 
commands for efficient file transfers to and from Amazon S3. 
11.3. Management Tools 
AWS provides management tools that allows customers to programmatically provision, monitor, 
and automate all the components of their cloud environment. Using these tools, they can 
maintain consistent controls without restricting development velocity. These services all work 
together and are integrated with every part of the AWS platform, allowing customers to have 
greater insight into their cloud environment as well as maintain logs necessary for audits. Our 
management tools include the following: 
• 
AWS Auto Scaling: Easily and safely scale multiple AWS resources. 
• 
Amazon CloudWatch: Collect and track metrics, collect and monitor log files, set alarms, 
and automatically react to changes in AWS resources. 
• 
AWS CloudFormation: Model and provision—in an automated and secure manner—all 
the resources needed for applications across all regions and accounts. 
• 
AWS CloudTrail: Automatically log, continuously monitor, and retain account activity 
related to actions across AWS infrastructure. 
• 
AWS Config: Inventory all configurations across AWS resources. 
• 
AWS Control Tower: Configure AWS management and security services based on 
established best practices in a secure, compliant, multi-account environment. 
• 
AWS License Manager: Manage licenses in AWS and on-premises servers from 
software vendors such as Microsoft, SAP, Oracle, and IBM. 
• 
AWS OpsWorks: Host and scale Chef Automate and Puppet Enterprise servers.

AWS Partner Package – US State and Local Government and Education
 
Use or disclosure of data contained on this sheet is subject to the restriction on the title page of this document 
Q2 2023 
45 
 
• 
AWS Personal Health Dashboard: View the performance and availability of the AWS 
Cloud services underlying AWS resources.  
• 
AWS Systems Manager: Centralize operational data from multiple AWS Cloud services 
and automate tasks across AWS resources. 
• 
AWS Service Catalog: Create, manage, and distribute catalogs of approved products to 
end users, who can then access the products they need in a personalized portal. 
• 
AWS Trusted Advisor: Provision resources by following best practices. 
• 
AWS Well-Architected Tool: Review the state of workloads and compare them to the 
latest AWS architectural best practices. 
AWS also offers several tools for cost management: 
• 
AWS Budgets: Set custom budgets that send alert when costs or usage exceed (or are 
forecasted to exceed) a budgeted amount. 
• 
AWS Cost and Usage Report: Customize a report that lists AWS usage for each service 
category used by an account and its IAM users in hourly or daily line items, as well as 
any activated tags for cost allocation purposes . 
• 
AWS Cost Explorer: Visualize, understand, and manage AWS costs and usage over 
time. 
12. Back-up and Disaster Recovery (DR) 
You can find more information in RFx Aid – Disaster Recovery and Resiliency. 
Customers of all sizes are using AWS to enable faster disaster recovery (DR) of their critical IT 
systems without incurring the infrastructure expense of a second physical site. AWS takes care 
of the undifferentiated heavy lifting required to create, implement, and manage scalable backup 
and recovery solutions.  
There are many advantages to using AWS as part of a data protection strategy: 
• 
Durability: Amazon S3, Amazon S3 Glacier, and S3 Glacier Deep Archive are designed 
for 99.999999999 percent of durability. Both platforms offer reliable backup of data, with 
object replication across at least three geographically dispersed Availability Zones. Many 
AWS services use Amazon S3 for storage and export/import operations. For example, 
Amazon Elastic Block Store (Amazon EBS) uses Amazon S3 for snapshot storage. 
• 
Security: AWS provides a number of options for access control and data encryption 
while in-transit and at-rest. 
• 
Global infrastructure: AWS services are available around the globe, so customers can 
back up and store data in the Region that meets their compliance and workload. 
• 
Compliance: AWS regularly achieves third-party validation for thousands of global 
compliance requirements that we continually monitor, so customers can easily fit the 
backup solution into their existing compliance regimen. Customers can access and 
download compliance reports through AWS Artifact. 
• 
Scalability: With AWS, customers don’t have to worry about capacity. As their needs 
change, they can scale their consumption up or down without administrative overhead. 
AWS Elastic Disaster Recovery (AWS DRS) continuously replicates customers’ machines 
(including operating system, system state configuration, databases, applications, and files) into 
a low-cost staging area in their target AWS account and preferred Region. In the case of a 
disaster, the customer can instruct CloudEndure Disaster Recovery to automatically launch 
thousands of their machines in their fully provisioned state in minutes.

AWS Partner Package – US State and Local Government and Education
 
Use or disclosure of data contained on this sheet is subject to the restriction on the title page of this document 
Q2 2023 
46 
 
Using these capabilities on our global infrastructure, customers can build a DR solution to fit 
their budget, recovery time objective (RTO), and recovery point objective (RPO) (depicted in 
Figure 10). An organization typically decides on an acceptable RTO and RPO based on the 
financial impact when systems are unavailable. The organization then plans solutions to provide 
cost-effective system recovery based on the RPO within the timeline and the service level 
established by the RTO. 
 
Figure 10: RPO and RTO. RPO relates to data loss in the event of a disaster; RTO relates to the amount 
of time systems are down.  
Figure 11 shows a spectrum of scenarios—backup and restore, pilot light, warm standby, and 
multi-site—arranged by how quickly a system can be available to users after a DR event. 
Typically, the shorter the recovery, the higher the cost of the solution. Each DR option is 
discussed in more detail below. 
 
 
Figure 11: Spectrum of DR Options. Customers can choose a preferred DR option based on 
preferences for cost and the time it takes to recover systems. 
12.1. Backup and Restore 
In most traditional environments, data is backed up to tape and sent offsite regularly. Recovery 
time is the longest using this method, and lack of automation leads to increased costs. Amazon 
S3 is ideal for backup data, as it is designed to provide 99.999999999% durability of objects 
over a given year. Amazon S3 offers a range of storage classes—including options for one-zone 
infrequent access and archive—to help save on costs. Transferring data to and from Amazon 
S3 is typically done via the network, and it is therefore accessible from any location. For a 
hybrid architecture, customers can use AWS Storage Gateway to automatically back up on-
premises data to Amazon S3. To centralize and automate their backup, AWS Backup allows 
customers to configure backup policies and monitor backup activity.

AWS Partner Package – US State and Local Government and Education
 
Use or disclosure of data contained on this sheet is subject to the restriction on the title page of this document 
Q2 2023 
47 
 
12.2. Pilot Light for Simple Recovery into AWS Warm Standby 
Solution 
In a gas heater, a small idle flame – called a pilot light – is always burning, and can quickly 
ignite the entire furnace to heat up a house as needed. This is analogous to the “pilot light” 
backup and restore approach. In this DR approach, customers replicate part of their IT structure 
for a limited set of core services in AWS. In the event of a disaster, the AWS cloud environment 
takes over. A small part of their infrastructure is always running, simultaneously syncing mutable 
data (such as databases or documents) while other parts of their infrastructure are switched off 
and used only during testing. Unlike a backup and recovery approach, the most critical core 
elements are already configured and running in AWS. When the time comes for recovery, the 
customer can rapidly provision a full-scale production environment around the critical core. The 
pilot light approach typically uses a compute service like Amazon EC2 or a database service 
like Amazon RDS.  
12.3. Warm Standby Solution in AWS 
The term “warm standby” is used to describe a DR scenario in which a scaled-down version of a 
fully functional environment is always running in the cloud. This decreases recovery time 
because some services are always running. By identifying business-critical systems, the 
customer can fully duplicate these systems on AWS and have them always on. These servers 
can run on a minimum-sized fleet of Amazon EC2 instances on the smallest sizes possible. This 
solution is not scaled to handle a full-production load, but it is fully functional. It can be used for 
non-production work, such as testing, quality assurance, and internal use. In a disaster, 
customers can scale out the system quickly to handle the production load by adding more 
instances. They can automate this process using Amazon EC2 Auto Scaling and Elastic Load 
Balancing. 
12.4. Multi-Site Solution Deployed on AWS and Onsite 
A multi-site solution runs in AWS and on the customer’s existing on-premises infrastructure in 
an active-active configuration. During a disaster situation, the customer sends all traffic to AWS 
servers, which can scale to handle the full production load. For this approach, customers can 
use a DNS service that supports weighted routing, such as Amazon Route 53, to route 
production traffic to different sites that deliver the same application or service. A proportion of 
traffic will go to the customer’s infrastructure in AWS, and the remainder will go to their onsite 
infrastructure. In an onsite disaster situation, the customer can adjust the DNS weighting and 
send all traffic to the AWS servers. The capacity of the AWS Cloud service can be rapidly 
increased to handle the full production load. Customers can automate this process using 
Amazon EC2 Auto Scaling and Elastic Load Balancing. 
13. Security Questionnaires  
Under the Shared Responsibility Model, AWS is responsible for security of the cloud: protecting 
the infrastructure that runs all of the services offered in the AWS Cloud. All other security in the 
cloud is dependent on the customer or AWS partner’s management of their account(s) and their 
solution. AWS personnel cannot fill out Security Questionnaires on behalf of our AWS Partners. 
In addition, AWS Partners maintain full control of their content and responsibility for configuring 
access to AWS services and resources. We provide an advanced set of access, encryption, and 
logging features to help AWS Partners do this effectively (for example, AWS Identity and 
Access Management, AWS Organizations and AWS CloudTrail). AWS Partners and customers

AWS Partner Package – US State and Local Government and Education
 
Use or disclosure of data contained on this sheet is subject to the restriction on the title page of this document 
Q2 2023 
48 
 
can choose how their content is secured. In the event that they need assistance to complete a 
questionnaire to document AWS security and compliance positions, we have the following 
resources to assist with understanding security on AWS. If AWS Partners have additional 
questions about a specific requirement, they can reach out to their AWS Account team for 
further information.  
• 
Compliance FAQs:This page answers frequently-asked questions about compliance.  
• 
AWS Artifact: AWS Artifact is a central resource for compliance-related information. It 
provides on-demand access to AWS’s security and compliance reports and select online 
agreements. The AWS SOC 2 report is particularly helpful for completing questionnaires 
because it provides a comprehensive description of the implementation and operating 
effectiveness of AWS security controls. Note that some AWS Artifact documentation is 
available under NDA, and use of the content is subject to the terms of that NDA. 
• 
CSA Consensus Assessments Initiative Questionnaire: The CSA Consensus 
Assessments Initiative Questionnaire provides a set of questions the CSA anticipates a 
cloud consumer and/or auditor would ask of a cloud provider. It provides a series of 
security, control, and process questions which can then be used for a wide range of 
uses, including cloud provider selection and security evaluation. This document contains 
the AWS answers to the CSA questionnaire. 
• 
AWS Risk and Compliance Whitepaper: This document addresses AWS-specific 
information around general cloud computing compliance questions. There are detailed 
descriptions of all AWS certifications, programs, reports, and third-party attestations.  
• 
AWS Data Center Controls Web Page: Many questionnaires have an entire section with 
questions related to data center physical security. This web page provides insight into 
some of our physical and environmental controls. 
• 
Data Privacy: This page details our data privacy and data security policies, practices, 
and technologies we’ve put in place. 
• 
AWS Security and Compliance Quick Reference Guide: This guide provides an overview 
of our assurance programs and how to secure content on the AWS Cloud. 
• 
AWS Compliance Center: This page offers a central location to research cloud-related 
regulatory requirements and how they impact various industries.  
14. AWS Public Sector Access Policy—Instructions  
If this opportunity requires the resale of AWS offerings, AWS Partners must include the AWS 
Public Sector Access Policy (“Access Policy”) in their response and incorporate the Access 
Policy in any agreement regarding such resale, per their Reseller Agreement, as amended. The 
Access Policy sets out rules, conditions, and restrictions regarding use of the AWS cloud 
services. This AWS Public Sector Access Policy can be accessed here.

AWS Partner Package – US State and Local Government and Education
 
Use or disclosure of data contained on this sheet is subject to the restriction on the title page of this document 
Q2 2023 
A-1 
 
Appendix A. Industry Analyst Reports on AWS Market 
Position 
[Note: “Do not edit content in this section, or use in a public document other than a direct RFx response. 
Include all citations and disclaimers outlined below.”] 
You can find more information in RFx Aid – Analyst Reports. 
AWS offers reports from trusted third-party analysts to help organizations understand the 
benefits and value of the AWS Cloud. The AWS in Analyst Research page provides reports and 
analysis from firms such as Gartner, IDC, and Forrester covering a variety of product categories 
and geographies. 
Gartner, Inc., a leading information technology research company, recently released its 2022 
Magic Quadrant for Cloud Infrastructure and Platform Services2 3 report. In Gartner's evaluation 
covering both cloud infrastructure and platform services (IaaS & PaaS, or "CIPS"), AWS is 
evaluated as a Leader placed highest in both axes of measurement: Ability to Execute and 
Completeness of Vision (see Figure 12). This is the twelfth consecutive year that Gartner has 
recognized AWS as a Leader in the Magic Quadrant, making AWS the longest-running CIPS 
Magic Quadrant Leader.  
                                               
2 Gartner, Magic Quadrant for Cloud Infrastructure & Platform Services, Raj Bala, Dennis Smith, Kevin Ji, 
David Wright, Miguel Angel Borrega, 19 October 2022. Gartner and Magic Quadrant are registered 
trademarks of Gartner, Inc. and/or its affiliates in the U.S. and internationally and is used herein with 
permission. All rights reserved. Gartner does not endorse any vendor, product or service depicted in its 
research publications, and does not advise technology users to select only those vendors with the highest 
ratings. Gartner research publications consist of the opinions of Gartner's research organization and 
should not be construed as statements of fact. Gartner disclaims all warranties, expressed or implied, with 
respect to this research, including any warranties of merchantability or fitness for a particular purpose. 
3 All statements in this report attributable to Gartner represent AWS’s interpretation of data, research 
opinion or viewpoints published as part of a syndicated subscription service by Gartner, Inc., and have 
not been reviewed by Gartner. Each Gartner publication speaks as of its original publication date (and not 
as of the date of this proposal). The opinions expressed in Gartner publications are not representations of 
fact and are subject to change without notice.

AWS Partner Package – US State and Local Government and Education
 
Use or disclosure of data contained on this sheet is subject to the restriction on the title page of this document 
Q2 2023 
A-2 
 
 
Figure 12: 2022 Gartner Magic Quadrant for Cloud Infrastructure and Platform Services 
More analyst reports can be found at AWS in Analyst Research.

AWS Partner Package 
 
 
 
 
Use or disclosure of data contained on this sheet is subject to the restriction on the title page of this document 
Q2 2023 
B-3 
 
Appendix B. AWS Resources 
B.1. AWS Overview 
• 
What is Cloud Computing: https://aws.amazon.com/what-is-cloud-computing/  
• 
Types of Cloud Computing: https://aws.amazon.com/types-of-cloud-computing/  
• 
About AWS: https://aws.amazon.com/about-aws/  
• 
AWS Global Infrastructure: https://aws.amazon.com/about-aws/global-infrastructure/  
B.2. AWS Solutions 
• 
Websites and Web Hosting: https://aws.amazon.com/websites/  
• 
Backup and Restore: https://aws.amazon.com/backup-restore/ 
• 
Data Archive: https://aws.amazon.com/archive/  
• 
Disaster Recovery: https://aws.amazon.com/disaster-recovery/  
• 
Big Data: https://aws.amazon.com/big-data/  
• 
High Performance Computing: https://aws.amazon.com/hpc/  
• 
Internet of Things: https://aws.amazon.com/iot/  
• 
Financial Services: https://aws.amazon.com/financial-services/  
• 
Healthcare and Life Sciences: https://aws.amazon.com/health/  
• 
Genomics: https://aws.amazon.com/health/genomics/  
• 
Business Applications: https://aws.amazon.com/business-applications/ 
• 
DevOps: https://aws.amazon.com/devops/  
B.3. AWS Products and Services 
• 
List of all AWS cloud services: https://aws.amazon.com/products/  
• 
AWS Marketplace: https://aws.amazon.com/marketplace/  
• 
AWS service documentation : http://aws.amazon.com/documentation/  
B.4. AWS in the Public Sector 
• 
AWS Public Sector Homepage: https://aws.amazon.com/government-education/  
• 
U.S. Federal Government: https://aws.amazon.com/federal/  
• 
State and Local Government: https://aws.amazon.com/stateandlocal/ 
• 
Defense and Aerospace: https://aws.amazon.com/government-education/defense/ 
• 
Education: https://aws.amazon.com/education/  
• 
Nonprofit Organizations: https://aws.amazon.com/government-education/nonprofits/  
• 
AWS GovCloud (US) Region: http://aws.amazon.com/govcloud-us/  
• 
AWS Government Partners: https://aws.amazon.com/partners/government/  
• 
AWS Public Sector Blog: https://aws.amazon.com/blogs/publicsector/  
B.5. AWS Partner Community 
• 
AWS Partner Network: https://aws.amazon.com/partners/  
• 
AWS Partner Directory: http://www.aws-partner-directory.com/

AWS Partner Package 
 
 
 
 
Use or disclosure of data contained on this sheet is subject to the restriction on the title page of this document 
Q2 2023 
B-4 
 
• 
AWS Partner Programs: https://aws.amazon.com/partners/programs/  
B.6. AWS Professional Services  
• 
AWS Professional Services: https://aws.amazon.com/professional-services/  
• 
AWS Cloud Adoption Framework: https://aws.amazon.com/professional-services/CAF/  
B.7. AWS Pricing 
• 
AWS Pricing Overview: http://aws.amazon.com/pricing/  
• 
AWS Economics Center: https://aws.amazon.com/economics/ 
• 
Cloud Financial Management: https://aws.amazon.com/aws-cost-management/ 
• 
AWS TCO Calculator: http://aws.amazon.com/tco-calculator/ 
B.8. AWS Billing 
• 
AWS Billing and Cost Management: 
http://docs.aws.amazon.com/awsaccountbilling/latest/aboutv2/billing-what-is.html  
• 
Consolidated Billing: http://docs.aws.amazon.com/awsaccountbilling/latest/aboutv2/consolidated-
billing.html  
• 
Cost Explorer: http://docs.aws.amazon.com/awsaccountbilling/latest/aboutv2/cost-explorer-what-
is.html  
• 
AWS Budgets and Forecasts: 
http://docs.aws.amazon.com/awsaccountbilling/latest/aboutv2/budgets-managing-costs.html  
B.9. AWS Security and Compliance 
• 
AWS Security Center: http://aws.amazon.com/security/  
• 
AWS Shared Responsibility Model: http://aws.amazon.com/security/sharing-the-security-
responsibility/  
• 
AWS Compliance: http://aws.amazon.com/compliance/  
• 
AWS Data Privacy: http://aws.amazon.com/compliance/data-privacy-faq/  
• 
Access Control: http://aws.amazon.com/iam/  
• 
AWS Security Blog: https://blogs.aws.amazon.com/security/  
B.10. AWS Support 
• 
AWS Support Tiers : https://aws.amazon.com/premiumsupport/  
• 
Support Knowledge Center: https://aws.amazon.com/premiumsupport/knowledge-center/  
• 
AWS Trusted Advisor: https://aws.amazon.com/premiumsupport/trustedadvisor/  
B.11. AWS Training and Best Practices 
• 
AWS Training and Certification: http://aws.amazon.com/training/  
• 
AWS Architecture Center: http://aws.amazon.com/architecture/  
• 
AWS Quick Starts: https://aws.amazon.com/quickstart/

AWS Partner Package 
 
 
 
 
Use or disclosure of data contained on this sheet is subject to the restriction on the title page of this document 
Q2 2023 
B-5 
 
B.12. Industry Analysis 
• 
Analyst Reports: http://aws.amazon.com/resources/analyst-reports/  
• 
Gartner Magic Quadrant for Cloud Infrastructure and Platform Services (October 2022):  
https://www.gartner.com/doc/reprints?id=1-2AOZQAQL&ct=220728&st=sb  
• 
IDC Report: Quantifying the Business Value of Amazon Web Services: 
http://d0.awsstatic.com/analyst-reports/IDC Business Value of AWS May 2015.pdf  
B.13. AWS Case Studies 
• 
AWS Case Studies: https://aws.amazon.com/solutions/case-studies/  
B.14. Procurement 
• 
AWS Public Sector Contract Center: http://aws.amazon.com/contract-center/  
• 
10 Considerations for a Cloud Procurement Whitepaper: http://d0.awsstatic.com/whitepapers/10-
considerations-for-a-cloud-procurement.pdf  
• 
How to Buy Cloud Computing Services for your Agency (Webinar): 
https://aws.amazon.com/webinars/buying-cloud-computing-services/  
B.15. Legal 
• 
AWS Customer Agreement: http://aws.amazon.com/agreement/  
• 
AWS Service Terms: https://aws.amazon.com/service-terms/  
• 
AWS Acceptable Use Policy: http://aws.amazon.com/aup/  
• 
AWS Trademark Guidelines: http://aws.amazon.com/trademark-guidelines/  
• 
AWS Site Terms: http://aws.amazon.com/terms/  
• 
AWS Privacy Notice: https://aws.amazon.com/privacy/  
• 
AWS Tax Help: http://aws.amazon.com/tax-help/  
B.16. Additional Resources 
• 
AWS Blog: https://aws.amazon.com/blogs/aws/ 
• 
AWS Discussion Forums: https://forums.aws.amazon.com/index.jspa  
• 
What’s New from AWS: http://aws.amazon.com/new/  
• 
AWS YouTube Channel: https://www.youtube.com/user/AmazonWebServices  
• 
AWS Twitter Feed: https://twitter.com/awscloud  
• 
AWS on SlideShare: http://www.slideshare.net/AmazonWebServices  
• 
Events and Webinars: https://aws.amazon.com/about-aws/events/  
• 
An E-Book of Cloud Best Practices: https://medium.com/aws-enterprise-collection/an-e-book-of-
cloud-best-practices-for-your-enterprise-4a211840c55b#.corzpjf3m  
B.17. AWS Whitepapers 
• 
AWS Whitepapers and Guides: http://aws.amazon.com/whitepapers/  
• 
Overview of AWS Whitepaper: http://d0.awsstatic.com/whitepapers/aws-overview.pdf  
• 
Security Resources and Whitepapers: http://aws.amazon.com/security/security-resources/  
• 
AWS Compliance whitepapers: http://aws.amazon.com/compliance/aws-whitepapers/

AWS Partner Package 
 
 
 
 
Use or disclosure of data contained on this sheet is subject to the restriction on the title page of this document 
Q2 2023 
B-6 
 
• 
Best Practices for Security, Identity, & Compliance: https://aws.amazon.com/architecture/security-
identity-compliance  
• 
AWS Risk and Compliance Whitepaper: 
https://d0.awsstatic.com/whitepapers/compliance/AWS Risk and Compliance Whitepaper.pdf

AWS Partner Package 
 
 
 
 
Q2 2023 
 
Page C-7 
 
Use or disclosure of data contained on this sheet is subject to the restriction on the title page of this document.  
Appendix C. Common AWS Certifications 
C.1. Federal Risk and Authorization Management Program (FedRAMP) 
Federal Risk and Authorization Management Program (FedRAMP) is a US government-wide 
program that delivers a standard approach to the security assessment, authorization, and 
continuous monitoring for cloud products and services. The governing bodies of FedRAMP 
include the Office of Management and Budget (OMB), US General Services Administration 
(GSA), US Department of Homeland Security (DHS), US Department of Defense (DoD), 
National Institutes of Standards & Technology (NIST), and the Federal Chief Information 
Officers (CIO) Council. 
Cloud services providers (CSPs) like AWS who want to offer their products and services to the 
US government must demonstrate FedRAMP compliance. FedRAMP uses the NIST Special 
Publication 800 series and requires CSPs to receive an independent security assessment 
conducted by a third-party assessment organization (3PAO) to ensure that authorizations are 
compliant with the Federal Information Security Management Act (FISMA). 
There are two paths for CSPs to be FedRAMP compliant: 
• 
Joint Authorization Board (JAB) Authorization – To receive FedRAMP JAB 
Provisional Authority to Operate (P-ATO), a CSP is reviewed by the FedRAMP Program 
Management Office (PMO), is assessed by a FedRAMP-accredited 3PAO, and receives 
a P-ATO from the JAB. The JAB is made up of the CIOs from DoD, DHS, and GSA. 
• 
Agency Authorization – To receive FedRAMP Agency Authority to Operate (ATO), a 
CSP is reviewed by a customer Agency CIO or Delegated Authorizing Official(s) to 
achieve a FedRAMP-compliant ATO that is verified by the FedRAMP PMO. 
AWS and FedRAMP 
AWS offers the following FedRAMP compliant systems that have been granted authorizations: 
• 
AWS GovCloud (US), which has been granted a JAB P-ATO and multiple ATOs for 
high impact level. The services in scope of the AWS GovCloud (US) JAB P-ATO 
boundary at high baseline security categorization can be found within the AWS Services 
in Scope by Compliance Program. 
• 
AWS US East-West, which has been granted a JAB P-ATO and multiple ATOs for 
moderate impact level. The services in scope of the AWS US East-West JAB P-ATO 
boundary at moderate baseline security categorization can be found within the AWS 
Services in Scope by Compliance Program. 
FedRAMP for AWS Partners 
AWS Partners and prospective customers can request access to the AWS APN Partner 
FedRAMP Security Package using AWS Artifact. Note that some AWS Artifact documentation is 
available under NDA, and use of the content is subject to the terms of that NDA. 
C.2. Federal Information Processing Standard (FIPS) 
The Federal Information Processing Standard (FIPS Publication 140-2) is a US government 
standard that specifies the security requirements for cryptographic modules that protect 
sensitive information.

AWS Partner Package 
 
 
 
 
Q2 2023 
 
Page C-8 
 
Use or disclosure of data contained on this sheet is subject to the restriction on the title page of this document.  
AWS and FIPS 
AWS works with customers to provide the information they need to manage compliance when 
using the AWS US East-West or AWS GovCloud (US) Regions. For more information about the 
standard, see Cryptographic Module Validation Program on the NIST Computer Security 
Resource Center website. 
FIPS for AWS Partners 
The Amazon VPC VPN endpoints in the AWS GovCloud (US) Regions operate using FIPS 140-
2 validated cryptographic modules. If you require use of FIPS 140-2 validated cryptographic 
modules when accessing AWS US East/West or AWS GovCloud (US) through use of the CLI or 
programmatically by using the APIs, the list of available FIPS endpoints by AWS Region can be 
found on our FIPS Publication 140-2 page.  
C.3. International Organization for Standardization (ISO) 9001:2015 
The International Organization for Standardization (ISO 9001:2015) outlines a process-oriented 
approach to documenting and reviewing the structure, responsibilities, and procedures required 
to achieve effective quality management within an organization. The key to the ongoing 
certification under this standard is establishing, maintaining, and improving the organizational 
structure, responsibilities, procedures, processes, and resources in a manner in which AWS 
products and services consistently satisfy ISO 9001:2015 quality requirements. 
AWS and ISO 9001:2015 
AWS has undergone a systematic, independent examination of our quality system to determine 
whether the activities and activity outputs comply with ISO 9001:2015 requirements. A certifying 
agent found our quality management system to comply with the requirements of ISO 9001:2015 
for the activities described in the scope of registration. You can download AWS’s ISO 
9001:2015 certification from our website.  
ISO 9001:2015 for AWS Partners 
The certification covers the quality management system over a specified scope of AWS Cloud 
services and Regions of operations. If you are pursuing ISO 9001:2015 certification while 
operating all or part of your IT systems on the AWS Cloud, you are not automatically certified by 
association. However, using an ISO 9001:2015 certified provider like AWS can make your 
certification process easier. 
C.4. ISO/International Electrotechnical Commission 27001:2013 
ISO/International Electrotechnical Commission (IEC) 27001:2013 is a security management 
standard that specifies security management best practices and comprehensive security 
controls following the ISO/IEC 27002 best practice guidance. The basis of this certification is the 
development and implementation of a rigorous security program, which includes the 
development and implementation of an Information Security Management System (ISMS) which 
defines how AWS perpetually manages security in a holistic, comprehensive manner. This 
widely-recognized international security standard specifies that AWS do the following: 
• 
Systematically evaluate our information security risks, taking into account the impact of 
threats and vulnerabilities.

AWS Partner Package 
 
 
 
 
Q2 2023 
 
Page C-9 
 
Use or disclosure of data contained on this sheet is subject to the restriction on the title page of this document.  
• 
Design and implement a comprehensive suite of information security controls and other 
forms of risk management to address customer and architecture security risks. 
• 
Have an overarching management process to ensure that the information security 
controls meet our needs on an ongoing basis. 
AWS and ISO/IEC 27001:2013 
AWS has certification for compliance with ISO/IEC 27001:2013, 27017:2015, and 27018:2014. 
These certifications are performed by independent third-party auditors. AWS’s ISO/IEC 
27001:2013 certification can be downloaded from our website.  
ISO/IEC 27001:2013 for AWS Partners 
The ISO/IEC 27001:2013 certification for AWS covers the AWS security management process 
over a specified scope of services and data centers. If you are pursuing ISO/IEC certifications 
while operating part or all of your IT on the AWS Cloud, you are not automatically certified by 
association. However, using an ISO/IEC 27001:2013 certified provider like AWS can make your 
certification process easier.  
C.5. ISO/IEC 27017:2015 
ISO/IEC 27017:2015 provides guidance on the information security aspects of cloud computing, 
recommending the implementation of cloud-specific information security controls that 
supplement the guidance of the ISO/IEC 27002 and ISO/IEC 27001 standards. This code of 
practice provides additional information security controls implementation guidance specific to 
CSPs like AWS.  
AWS and ISO/IEC 27017:2015 
AWS’s attestation to the ISO/IEC 27017:2015 guidance not only demonstrates our ongoing 
commitment to align with globally-recognized best practices, but also verifies that AWS has a 
system of highly precise controls in place that are specific to cloud services. AWS’s ISO/IEC 
27017:2015 certification can be downloaded from our website.  
ISO/IEC 27017:2015 for AWS Partners 
AWS’s ISO/IEC 27017:2015 certification covers the security management process and cloud 
provider specific controls. If you are pursuing ISO/IEC certifications while operating part or all of 
your IT environment on the AWS Cloud, you are not automatically certified by association. 
However, using an ISO/IEC 27017:2015 certified provider like AWS can make your certification 
process easier. The AWS ISO/IEC 27017:2015 assessment provides evidence that our security 
controls are aligned with the 27017:2015 guidance specific to CSPs. 
C.6. ISO/IEC 27018:2019 
ISO/IEC 27018:2019 is a code of practice that focuses on protection of personal data in the 
cloud. It is based on ISO/IEC information security standard 27002 and provides implementation 
guidance on ISO/IEC 27002 controls applicable to public cloud personally identifiable 
information (PII). It also provides a set of additional controls and associated guidance intended 
to address public cloud PII protection requirements not addressed by the existing ISO/IEC 
27002 control set. 
AWS and ISO/IEC 27018:2019

AWS Partner Package 
 
 
 
 
Q2 2023 
 
Page C-10 
 
Use or disclosure of data contained on this sheet is subject to the restriction on the title page of this document.  
AWS maintains the high bar of data protection and privacy controls outlined in ISO/IEC 
27018:2014 for all customer content, regardless of whether or not any particular data is PII. 
AWS’s ISO/IEC 27018:2019 certification can be downloaded from our website.  
ISO/IEC 27018:2019 for AWS Partners 
Alignment demonstrates to customers that AWS has a system of controls in place that 
specifically address the privacy protection of their content. AWS’s alignment with and 
independent third-party assessment of this internationally recognized code of practice 
demonstrates AWS’s commitment to the privacy and protection of customers’ content.  
C.7. Payment Card Industry Data Security Standard (PCI DSS) 
The Payment Card Industry Data Security Standard (PCI DSS Level 1) is a proprietary 
information security standard administered by the PCI Security Standards Council, which was 
founded by American Express, Discover Financial Services, JCB International, MasterCard 
Worldwide, and Visa Inc. 
PCI DSS applies to all entities that store, process, or transmit cardholder data (CHD) or 
sensitive authentication data (SAD), including merchants, processors, acquirers, issuers, and 
service providers. PCI DSS is mandated by the card brands and administered by the PCI 
Security Standards Council. 
AWS and PCI DSS 
AWS is certified as a PCI DSS 3.2 Level 1 Service Provider, the highest level of assessment 
available. The compliance assessment was conducted by Coalfire Systems Inc., an 
independent Qualified Security Assessor (QSA). The PCI DSS Attestation of Compliance (AOC) 
and Responsibility Summary is available to AWS customers by using AWS Artifact. Note that 
some AWS Artifact documentation is available under NDA and use of the content is subject to 
the terms of that NDA. 
PCI DSS for AWS Partners 
As a customer who uses AWS products and services to store, process, or transmit cardholder 
data, you can rely on AWS technology infrastructure as you manage your own PCI DSS 
compliance certification. 
AWS does not directly store, transmit, or process any customer CHD. However, you may create 
your own cardholder data environment (CDE) that can store, transmit, or process cardholder 
data using AWS products. 
Customers must manage their own PCI DSS compliance certification, and additional testing will 
be required to verify that your environment satisfies all PCS DSS requirements. However, for 
the portion of the PCI CDE that is deployed in AWS, your QSA can rely on AWS AOC without 
further testing. 
C.8. System and Organization Control (SOC) Reports 
AWS System and Organization Control (SOC Reports) are independent third-party examination 
reports that demonstrate how AWS achieves key compliance controls and objectives. The 
purpose of these reports is to help you and your auditors understand the AWS controls 
established to support operations and compliance. Table 3 describes the four AWS SOC 
Reports.

AWS Partner Package 
 
 
 
 
Q2 2023 
 
Page C-11 
 
Use or disclosure of data contained on this sheet is subject to the restriction on the title page of this document.