Broad-Based Black Economic Empowerment Act (B-BBEE Act)
Act 53 of 2003
Provides the empowerment-compliance context often used in public-sector supplier evaluation.
Relevant because this is a South African public-sector procurement opportunity.
Documents available on tender detail page
Tender Type
Request for Bid(Open-Tender)
Delivery Location
Cnr 497 Sophie de Bruyn & Jeff Masemola Streets - Pretoria - Pretoria - 0002
Organization Type
GOVERNMENT
Published
21 Aug 2026
OCDS Reference
ocds-9t57fa-166546
Comprehensive information security and cybersecurity services are required by postbank soc for a period of three years, covering a 24/7 security operations centre, endpoint protection, zero-trust network security, identity and access management, privileged access management, data protection, incident response, threat intelligence, and governance. The most consequential requirement is the mandatory minimum of 70 out of 100 points on functionality evaluation, with strict slas including a 15-minute mean time to detect and 30-minute mean time to respond, and the provider must hold professional indemnity insurance of at least r20 million and be certified or partnered with at least three of iso 27001, pci dss qsa, cissp, ceh, or oscp.
Closing date and submission: 18 September 2026 at 11:00 am, emailed to [email protected]. Late bids are not accepted.
Non-compulsory briefing: 31 August 2026 at 11:00 am via Microsoft Teams (Meeting ID: 353 842 123 818 395, Passcode: M8hs2Ye6).
Mandatory documents: completed SBD 1, SBD 7, and SBD 4; tax compliance (TCS PIN or CSD number); B-BBEE certificate; confirmation letter; team credentials (CISO, CISSP); proof of physical office in South Africa; technical response document; and recovery assurance capability.
Eligibility: CSD registration, valid tax clearance, and B-BBEE compliance. The provider must be certified or formally partnered with at least three of ISO 27001, PCI DSS QSA, CISSP, CEH, or OSCP.
Evaluation: Phase 1 – mandatory pass; Phase 2 – functionality out of 100 points (minimum 70 to proceed); Phase 3 – live demonstration for shortlisted bidders; Phase 4 – commercial evaluation using 80/20 or 90/10 preference point system.
Special conditions: no upfront payment; professional indemnity insurance of at least R20 million; all infrastructure and data must remain within South Africa; all personnel must pass ITC and criminal background clearance; a transition-out plan must be submitted within six months of contract start.
Service level agreements: MTTD 15 minutes, MTTR 30 minutes, critical patch compliance at least 95% within 7 days, SOC uptime 99.9%, ransomware recovery success 100%, critical incident containment within 60 minutes, and identity compromise containment within 15 minutes.
Continue with tenders sharing this issuer, category, or province.
Return to this tender’s issuing organisation, province, or category.
Continue with tenders sharing this issuer, category, or province.
Date & Time
Friday, 18 September 2026 - 11:00
Venue
Microsoft Teams
Categories
Request for Bid(Open-Tender)
Cnr 497 Sophie de Bruyn & Jeff Masemola Streets - Pretoria - Pretoria - 0002
Tenders in this industry often require registration with these bodies.
Recommended Certifications
Having these can improve your winning chances: IITPSA Membership, ISO 27001 (Information Security Management), ISO 20000 (IT Service Management), CISSP
AI Document Analysis Stages
Description
Source: RFP No. 04-06-26-27 - Cybersecurity Services.pdf21 Aug
2026
Tender Published
Tender was published
18 Sept
2026
Closing Date
Tender closing date
These references help suppliers understand the public-procurement framework around this opportunity. They are generated from the tender category, issuing organisation type and procurement context.
These rules commonly apply to South African public-sector procurement.
Act 53 of 2003
Provides the empowerment-compliance context often used in public-sector supplier evaluation.
Relevant because this is a South African public-sector procurement opportunity.
Act 108 of 1996 (s217)
This is general procurement context, not legal advice. Always verify requirements in the official tender documents and issuing authority notices.
RFP No. 04-06-26-27 - Cybersecurity Services.pdf
The Postbank SOC is seeking to appoint a qualified and experienced service provider to deliver comprehensive Information Security and Cybersecurity services for a period of three years. The objective is to ensure that Postbank's critical banking infrastructure and office productivity environments are fully protected against cyber threats.
To download these documents and access AI-powered analysis, visit the main tender page.
Matched by category & region
Free guidance to prepare before you bid
Not sure if your business is ready for this tender? Check CSD, CIDB, and B-BBEE requirements, run a readiness assessment, and move from opportunity to submission.
Open Supplier Readiness HubLearn how to submit a winning bid with these related articles
We refine every tender document through these stages so you can brief your team and prepare your bid with confidence. Anything marked as "in progress" will be upgraded automatically — no action required from you.
The appointment of a qualified and experienced service provider to deliver comprehensive Information Security and Cybersecurity services for a period of three (3) years. RFB/P issuing date: 21 August 2026. Closing date: 18 September 2026 at 11:00 am. Submission email: [email protected]. Validity period: 180 days from closing date.
Important Dates
Source: RFP No. 04-06-26-27 - Cybersecurity Services.pdf (RFP)Non-compulsory briefing: 31 August 2026 at 11:00 am via Microsoft Teams. Meeting ID: 353 842 123 818 395, Passcode: M8hs2Ye6.
Closing: 18 September 2026 at 11:00 am.
Bid validity: 180 days from closing.
Briefing Session
Source: RFP No. 04-06-26-27 - Cybersecurity Services.pdf (RFP)Non-compulsory briefing session: 31 August 2026 at 11:00 am via Microsoft Teams. Meeting ID: 353 842 123 818 395, Passcode: M8hs2Ye6.
Contact Information
Source: RFP No. 04-06-26-27 - Cybersecurity Services.pdf (RFP)Submission email: [email protected]
Enquiries: Vusi Maditsi ([email protected]) and Thabo Mokhabi ([email protected])
Submission Guidelines
Source: RFP No. 04-06-26-27 - Cybersecurity Services.pdf (RFP)Submission channel: email to [email protected].
Closing: 18 September 2026 at 11:00 am. Late bids not accepted.
Bids must be on official forms provided (SBD 1, SBD 7) and not re-typed.
Returnable documents: SBD 1 (Invitation to Bid), SBD 7 (Contract Form), proof of tax compliance (TCS PIN or CSD number), and mandatory documents: confirmation letter, team credentials (CISO, CISSP), proof of physical office in South Africa, technical response document, recovery assurance capability.
Disqualification risks: unsigned forms, missing mandatory documents, late submission, non-compliance with tax or CSD requirements.
Evaluation Criteria
Source: RFP No. 04-06-26-27 - Cybersecurity Services.pdf (RFP)Phase 1: Mandatory requirements (confirmation letter, team credentials, office, technical response, recovery assurance). Must pass.
Phase 2: Functionality scored out of 100 points. Four sub-criteria each 25 points: Cyber Defense & Ransomware Strategy, Recovery & Cyber Resilience, SOC & Incident Response Operating Model, Financial Sector Delivery Depth. Minimum 70 points to proceed.
Phase 3: Live demonstration for shortlisted bidders.
Phase 4: Commercial evaluation using 80/20 or 90/10 preference point system (price and specific goals).
Independent verification rights reserved.
Technical Specifications
Source: RFP No. 04-06-26-27 - Cybersecurity Services.pdf (RFP)Scope: Comprehensive managed cybersecurity services for Postbank for 3 years.
Key service areas: 24/7 Security Operations Centre (SOC), Endpoint Detection and Response (EDR/XDR), Zero Trust Network Security, Identity and Access Management (IGA, MFA, SSO), Privileged Access Management (PAM), Data Protection (DLP, encryption, HSM), Incident Response and Forensics, Threat Intelligence, Cybersecurity Governance, Awareness and Insider Threat Management, Audit and Compliance, Security Device Management, Email and Communication Security, Patch and Vulnerability Management, Cloud and Application Security.
Deliverables: Deployment roadmap, monthly/quarterly reports, annual threat intelligence report, ransomware readiness report, cyber recovery validation, knowledge transfer, and exit migration package.
SLAs: MTTD 15 min, MTTR 30 min, patch compliance 95% within 7 days (critical), SOC uptime 99.9%, ransomware recovery 100%, critical incident containment within 60 min, identity compromise containment within 15 min, critical asset log coverage >=95%, EDR/XDR coverage >=95%, overdue critical vulnerability rate <=5%, quarterly training attendance >=90%.
Insurance: Professional Indemnity minimum R20 million.
Certifications: Provider must be certified/partnered with at least 3 of ISO 27001, PCI DSS QSA, CISSP, CEH, OSCP.
Data sovereignty: All infrastructure and data within South Africa.
Personnel vetting: ITC and criminal clearance required.
Methodology
Source: RFP No. 04-06-26-27 - Cybersecurity Services.pdfScope of work includes 15 service areas: SOC, Endpoint Security, Zero Trust Network, Identity and Authentication, PAM, Data Protection, Incident Response, Threat Intelligence, Governance, Awareness, Audit, Security Device Management, Email Security, Patch Management, Cloud Security. Deliverables include deployment roadmap, documentation, reports, knowledge transfer, and exit plan. SLAs: MTTD 15 min, MTTR 30 min, patch compliance 95% within 7 days, SOC uptime 99.9%, ransomware recovery 100%, etc.
Experience & Qualifications
Source: RFP No. 04-06-26-27 - Cybersecurity Services.pdfTeam credentials: minimum two certified resources - CISO and CISSP. References: Technical Response Document must demonstrate experience in managed cybersecurity services for a regulated financial institution (bank, payment institution, insurer) or equivalent in last 3 years. Evaluation criterion 'Financial Sector Delivery Depth' (25 points) assesses past experience with banking/financial clients.
Quality Management
Source: RFP No. 04-06-26-27 - Cybersecurity Services.pdfCompliance with SARB, POPIA, PCI DSS, ISO 27001, NIST CSF. Must maintain ISMS, quarterly compliance assessments, support for PCI DSS certification, risk register, cyber resilience evidence packs. Quarterly risk and compliance reports. Control mapping required.
Pricing Schedule
Source: RFP No. 04-06-26-27 - Cybersecurity Services.pdfThe bid must include a completed pricing schedule/costing model as per the provided format. No upfront payment. Professional Indemnity Insurance of R20 million required.
Financial Requirements
Source: RFP No. 04-06-26-27 - Cybersecurity Services.pdf (RFP)No upfront payment.
Pricing must be submitted on the provided Pricing Schedule/Costing Model.
Professional Indemnity Insurance of at least R20 million required.
Bid validity 180 days.
Compliance Requirements
Source: RFP No. 04-06-26-27 - Cybersecurity Services.pdf (RFP)CSD registration required.
Tax compliance: Submit TCS PIN or CSD number. Must be valid.
B-BBEE: PPPFA applies. Preference points system (80/20 or 90/10) for price and specific goals.
Mandatory documents: proof of CSD, tax compliance, B-BBEE certificate.
Provider must have certifications: ISO 27001, PCI DSS, etc. as per technical specs.
Local content: Not specified.
B-BBEE Requirements
Source: RFP No. 04-06-26-27 - Cybersecurity Services.pdf (RFP)Postbank supports B-BBEE. The PPPFA and Preferential Procurement Regulations 2022 apply. Bidders must demonstrate commitment to B-BBEE in ownership, skills transfer, employment equity, and procurement practices. Preference points will be awarded based on price and specific goals.
Contractual Terms
Source: RFP No. 04-06-26-27 - Cybersecurity Services.pdfJoint Controls and Transparency: Postbank gets direct access to logs, dashboards, vulnerability results. Bidder must not obstruct audits or forensic investigations. Quarterly governance reviews. Annual cyber resilience stress testing. Exit and Handover: transition plan within 6 months, handover program 6 months before expiry, complete documentation, training, tooling portability. Final objective: seamless handover without degradation.
Special Conditions
Source: RFP No. 04-06-26-27 - Cybersecurity Services.pdf (RFP)No upfront payment. Postbank may request written clarification, cancel or reject any proposal, not award to lowest bidder, or award parts. Bidders accept evaluation criteria. Postbank may conduct benchmarks. Changing wording will be evaluated as original. Subject to Government Procurement General Conditions and Special Conditions. Postbank may verify information, not accept any quotation, cancel or re-issue. Special conditions of contract: integrated operating model, personnel vetting (ITC and criminal clearance), participation in scenario-based reviews and simulations, full support during major incidents.
Requirements
Source: RFP No. 04-06-26-27 - Cybersecurity Services.pdf (RFP)Mandatory requirements: 1) Confirmation letter on company letterhead confirming full compliance. 2) Team credentials: minimum two certified resources (CISO and CISSP). 3) Physical office in South Africa (preferably Pretoria or Johannesburg) with proof. 4) Technical Response Document demonstrating experience in managed services for regulated financial institution in last 3 years. 5) Recovery Assurance Capability: compliance reports for PCI DSS (ROC), ISO27001, and POPIA.
Section
Source: RFP No. 04-06-26-27 - Cybersecurity Services.pdfEvaluation Phases: Phase 1 - Mandatory Requirements (confirmation letter, team credentials, office location, references, recovery assurance). Phase 2 - Functionality (100 points: Cyber Defense & Ransomware Strategy 25, Recovery & Cyber Resilience 25, SOC & Incident Response Operating Model 25, Financial Sector Delivery Depth 25). Minimum 70 points. Phase 3 - Live Demonstration. Phase 4 - Commercial: Price and Specific Goals under 80/20 or 90/10 system. Independent verification rights reserved.
Sets the constitutional standard for fair, equitable, transparent, competitive and cost-effective public procurement.
Relevant because this is a South African public-sector procurement opportunity.
Act 5 of 2000
Covers preferential procurement and preference-point systems used in public tenders.
Relevant because this is a South African public-sector procurement opportunity.
Act 12 of 2004
Supports anti-corruption controls and supplier integrity in procurement processes.
Relevant because this is a South African public-sector procurement opportunity.
Act 28 of 2024
Provides the national framework for public procurement across government.
Relevant because this is a South African public-sector procurement opportunity.
Act 2 of 2000
Supports access to tender records, award decisions and public-sector procurement information.
Relevant because this is a South African public-sector procurement opportunity.
Act 3 of 2000
Supports lawful, reasonable and procedurally fair administrative tender decisions.
Relevant because this is a South African public-sector procurement opportunity.
Address
173 Nelson Mandela Dr, Westdene, Bloemfontein, 9301, South Africa
Source confidence
High source confidence
Official source
eTenders.gov.za
Documents found
1
Last checked
21 Aug 2026
AI status
Enhanced
Data conflicts
None detected
This tender has strong source evidence, including source metadata and supporting tender information synced from the government tender portal.
Tenders SA is not the issuing authority. All tenders are automatically synced from the official government tender portal. Always confirm final submission details, closing dates, briefing sessions, eligibility requirements, and documents on the official government portal before applying.
Contact
076-706-9269[email protected]www.postbank.co.za173 Nelson Mandela Dr, Westdene, Bloemfontein, 9301, South Africa
Key Personnel
Provinces Active
Industries
💡 Want more tendering tips and strategies?
Explore Our BlogMedian Estimate
R 3 920 605
Range
Based on 25 comparable awarded tenders. Companies with similar profiles typically bid near the median.
* Estimates are based on historical data and do not guarantee actual award values.
Get deep intelligence on Information and communication. Unlock full pricing strategies, bid frequency, and historical win rates.