18F / bpa-fedramp-dashboard

FedRAMP Dashboard BPA Order

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

Similar Experience that is not publicly available/shareable

adamjhorvath opened this issue · comments

Under RFQ Section 7d (Similar Experience) of the quotation instructions, it states “the summary shall include links to the public Git repository that includes the source code that was developed and accepted for the project.”

Often firms will have lots of relevant experience that may not be public and/or may be protected by confidentiality; this is very often the case. Past clients will not always be able to easily share this information and certainly will not want such information being posted publicly.

Given the confidentiality, ownership, and use restrictions with client projects, we kindly request the government revise this requirement such that if artifacts developed for a client (source code, screen shots, etc) must be provided as part of the evaluation and proposal criteria that it is done so under a Non-Disclosure and license process with the individual quoting Contractors - and circulated only to GSA personnel critical for evaluation of award.

I too have the same concern that is being raised by numerous vendors - that a number of our past performances are:

  • For commercial organizations and the property of that organization with private repositories
  • For federal organizations but not publicly accessible
  • Using a source code repository that is not Git (for legacy reasons)

Please see response to issue #11. GSA will not sign NDAs. If it is a private dashboard that cannot be viewed it is not comparable.