Broad-Based Black Economic Empowerment Act (B-BBEE Act)
Act 53 of 2003
Provides the empowerment-compliance context often used in public-sector supplier evaluation.
Relevant because this is a South African public-sector procurement opportunity.
Issuing Organization
Air Traffic and Navigation Services Company LimitedLocation
Gauteng
Closing Date
02 Oct 2026
Documents available on tender detail page
Tender Type
Request for Proposal
Delivery Location
ATNS Company Limited, Eastgate Office Park, Block C, - Bruma - Johannesburg - 2298
Organization Type
GOVERNMENT
Published
28 Aug 2026
OCDS Reference
ocds-9t57fa-167432
Atns seeks a qualified service provider to design, implement, operate, support, and maintain a fully integrated on-premises security operations centre (soc) for five years, covering continuous cybersecurity monitoring, threat detection, incident response, and protection of critical IT and ot (cns/atm) environments. The contract will be awarded under an 80/20 preference point system, with a minimum functionality threshold of 70 out of 100 points. Bidders must attend a compulsory briefing session and submit three parcels (administrative/mandatory, functionality, price/preference) by 02 october 2026, 14h00 cat.
Compulsory briefing session: Attend the Microsoft Teams briefing on 04 September 2026 at 12h00 CAT (Meeting ID: 313 830 782 874 929, Passcode: 2Rm7WK73); attendance registers and contact details must be provided.
Company experience: Provide at least three (3) contactable reference letters from enterprise clients confirming successful implementation and management of a SOC within the last five (5) years; letters must be on official letterhead, dated, signed, and include contact details.
On-premises deployment: Submit a detailed solution-architecture diagram demonstrating that the SOC will be deployed within ATNS designated data centres, clearly identifying storage, processing, and backup locations for security logs, incident data, telemetry, and forensic evidence; all security data must remain under ATNS control.
IT and OT monitoring capability: Provide technical references demonstrating support for both IT and ATM/CNS Operational Technology (OT) environments, including onboarding, monitoring, detection, and incident response capabilities.
Key personnel: Provide resource profiles and valid certifications for at least three (3) Tier-1 SOC Analysts and at least two (2) Tier-3 SOC Analysts, with required certifications (e.g., CISM, CEH, OSCP, GCIH, GCIA, Security+, vendor SIEM); certifications must be valid on the bid closing date.
Functionality threshold: Score at least 70 out of 100 points in the functionality stage (SIEM functional capability 35 points, log collection and integration 35 points, training 30 points); scoring zero on any individual criterion results in disqualification.
Price and preference: Bids are evaluated on an 80/20 system (price 80 points, specific goals 20 points); preference points are available for 51% Black Owned suppliers (10 points) and 30% Black Woman Owned suppliers (10 points), claimed via SBD 6.1 with supporting documents (CSD report, CIPC documents, shareholder certificates, ID copies, B-BBEE certificate or sworn affidavit).
Submission deadline: Submit by 02 October 2026, 14h00 CAT via the National Treasury e-Submission (e-Tender) system or hard copy (one original, one copy, one PDF on USB) to ATNS Company Limited, Eastgate Office Park, Block C, South Boulevard Road, Bruma, 2298; email submissions will not be accepted.
Validity period: Proposals must remain valid for 120 days from the closing date; extensions may be requested but are subject to ATNS approval.
Tax and registration: Provide a valid SARS Tax Compliance Status PIN (valid for the full validity period) and proof of CSD registration or application; bids without these will be deemed non-responsive.
Continue with tenders sharing this issuer, category, or province.
Return to this tender’s issuing organisation, province, or category.
Continue with tenders sharing this issuer, category, or province.
Date & Time
Friday, 02 October 2026 - 14:00
Venue
MS Teams
Important: Attendance at this briefing session is mandatory. Bids from suppliers who do not attend may be disqualified.
Compulsory briefing session date: 04 september 2026 time: 12h00 central african time (cat) platform: microsoft teams meeting ID: 313 830 782 874 929 passcode: 2rm7wk73
Categories
Request for Proposal
ATNS Company Limited, Eastgate Office Park, Block C, - Bruma - Johannesburg - 2298
Tenders in this industry often require registration with these bodies.
Recommended Certifications
Having these can improve your winning chances: IITPSA Membership, ISO 27001 (Information Security Management), ISO 20000 (IT Service Management), CISSP
AI Document Analysis Stages
Description
Source: Volume 1A - SOC.pdf28 Aug
2026
Tender Published
Tender was published
02 Oct
2026
Closing Date
Tender closing date
These references help suppliers understand the public-procurement framework around this opportunity. They are generated from the tender category, issuing organisation type and procurement context.
These rules commonly apply to South African public-sector procurement.
Act 53 of 2003
Provides the empowerment-compliance context often used in public-sector supplier evaluation.
Relevant because this is a South African public-sector procurement opportunity.
Act 108 of 1996 (s217)
This is general procurement context, not legal advice. Always verify requirements in the official tender documents and issuing authority notices.
Volume 1A - SOC.pdf
Appointment of a service provider to design, implement, operate, support, and maintain a fully integrated on-premises Security Operations Centre (SOC) for ATNS over five years, covering continuous cybersecurity monitoring, threat detection, incident response, threat intelligence, and protection of both IT and Operational Technology (OT) environments.
To download these documents and access AI-powered analysis, visit the main tender page.
Win ATNS tenders with AI Discovery, aviation-systems intelligence, compliance analysis, and structured support for navigation and training contracts.
Matched by category & region
Free guidance to prepare before you bid
Not sure if your business is ready for this tender? Check CSD, CIDB, and B-BBEE requirements, run a readiness assessment, and move from opportunity to submission.
Open Supplier Readiness HubMedian Estimate
R 3 085 221
Range
Based on 25 comparable awarded tenders. Companies with similar profiles typically bid near the median.
* Estimates are based on historical data and do not guarantee actual award values.
We refine every tender document through these stages so you can brief your team and prepare your bid with confidence. Anything marked as "in progress" will be upgraded automatically — no action required from you.
ATNS provides air traffic management, communication, surveillance, navigation, and related services, managing 6% of the world's airspace with over 1,100 staff across 21 aerodromes in South Africa. This tender appoints a service provider to design, implement, operate, support, and maintain a fully integrated on-premises Security Operations Centre (SOC) for ATNS over five years, providing continuous cybersecurity monitoring, threat detection, incident response, threat intelligence, security analytics, and protection of ATNS's critical IT and OT environments. Scope includes system design, implementation, monitoring of enterprise IT, CNS/ATM (OT), network infrastructure, security systems, identity management, applications, servers, and databases. Operational requirements include 24/7/365 SOC operations, continuous log ingestion, incident response and escalation, specialist expertise (threat hunting, forensics), and warranty and support services.
Important Dates
Source: Volume 1A - SOC.pdf (RFP)Closing date: 02 October 2026, 14h00 CAT. Clarification queries due: 18 September 2026, 17h00 CAT. Responses to queries: 25 September 2026. Compulsory briefing session: date not stated in the document (attendance required).
Contact Information
Source: Volume 1A - SOC.pdf (RFP)Pre-bid clarifications: Zanele Mbiza, Specialist: Demand Management, [email protected] (cc: [email protected]). Post-bid clarifications: Nhlanhla Mdamba, Specialist: Acquisition Management, [email protected] (cc: [email protected]). Technical enquiries: Nhlanhla Mdamba/Zanele Mbiza, 011 607 1325, [email protected]; [email protected]. Submission address: ATNS Company Limited, Eastgate Office Park, Block C, South Boulevard Road, Bruma, 2298, South Africa.
Submission Guidelines
Source: Volume 1A - SOC.pdf (RFP)Submit in three parcels (A: Administrative and Mandatory, B: Functionality, C: Price and Preference) via the online e-Submission (e-Tender) system or hard copy. Hard copies: one original, one copy, and one PDF on USB, delivered to ATNS Company Limited, Eastgate Office Park, Block C, South Boulevard Road, Bruma, 2298, South Africa, by 02 October 2026, 14h00 CAT. Bids must include completed and signed SBD 1, SBD 3.3, SBD 6.1, Declaration of Interest, CSD proof, tax compliance PIN, and all required supporting documents. Non-compliance with any administrative or mandatory requirement may lead to rejection or disqualification.
Evaluation Criteria
Source: Volume 1A - SOC.pdf (RFP)Four-stage evaluation: Stage 1 Administrative (SARS tax compliance PIN), Stage 2 Mandatory (compulsory briefing attendance, 3 SOC reference letters, on-premises architecture diagram, IT/OT monitoring capability, key personnel certifications), Stage 3 Functionality (minimum 70/100 points; SIEM functional capability 35 points, log collection and integration 35 points, training 30 points; scoring per number of documents/evidence provided), Stage 4 Price and Preference (80/20 system; price 80 points, specific goals 20 points). Bidders scoring zero on any individual criterion or below 70 functionality points are disqualified. Preference points: 10 points for 51% Black Owned, 10 points for 30% Black Woman Owned, claimed via SBD 6.1 with supporting documents.
Technical Specifications
Source: Volume 1A - SOC.pdf (RFP)Design, implement, operate, support, and maintain a fully integrated on-premises Security Operations Centre (SOC) for ATNS over five years. Scope includes: SOC architecture design and engineering; secure onboarding of existing systems; supply, installation, and configuration of hardware/software; SIEM implementation and tuning; SOAR deployment; incident response workflow implementation; threat intelligence integration; dashboard and reporting; security hardening; testing and commissioning. Systems to be monitored: enterprise IT, CNS/ATM (OT), network infrastructure, security systems (IDS/IPS, EDR), identity management, applications, servers, databases. Operational requirements: 24/7/365 monitoring, continuous log ingestion, incident response and escalation, threat hunting, forensics, warranty and support. SIEM functional capability must include 17 specified features (e.g., real-time log ingestion, correlation, DPI for OT protocols, custom rules, long-term retention, automated triage, playbook-driven response, threat intelligence, behavioural analytics). Log collection must support syslog, APIs, cloud connectors, agent-based/agentless collection, secure forwarding, passive OT traffic analysis, ticketing integration. Training deliverables: as-built documentation, user manuals, testing methodology and plan, training plan, knowledge transfer and skills transfer approach.
Methodology
Source: Volume 1A - SOC.pdfBidders must provide a detailed solution-architecture diagram demonstrating on-premises deployment within ATNS designated data centres, identifying storage, processing, and backup locations for security logs, incident data, telemetry, and forensic evidence. All security data must remain under ATNS control and within approved jurisdiction. For functionality, bidders must provide documentary evidence for SIEM functional capability (17 items), log collection and integration (8 items), and training (7 items), with screenshots, connector catalogues, integration guides, training plans, and skills transfer approach. Failure to provide supporting evidence results in zero for that criterion.
Experience & Qualifications
Source: Volume 1A - SOC.pdfCompany experience: minimum 3 contactable reference letters from enterprise clients confirming successful implementation and management of a SOC within the last 5 years. Reference letters must be on official letterhead, dated and signed by authorised representative, clearly confirm SOC implementation and management, include contact details for verification. Appointment letters, purchase orders, contracts, or award letters are not accepted as substitutes. Key personnel: at least 3 Tier-1 SOC Analysts and at least 2 Tier-3 SOC Analysts. Required certifications: CISM, CEH, OSCP, GCIH, GCIA, Global Information Assurance Certification, Computing Technology Industry Association Security+, Vendor SIEM Certifications – International Qualifications. Certifications must be valid on bid closing date. Tier-2 resources must demonstrate experience in security monitoring and incident triage; Tier-3 resources must demonstrate experience in incident response, threat hunting, and digital forensics. References must include contactable client details. Failure to submit valid and current documentation results in disqualification.
Quality Management
Source: Volume 1A - SOC.pdfQuality requirements are embedded in functionality evaluation: SIEM functional capability (35 points) requires evidence of real-time log ingestion, correlation and analytics, deep packet inspection for OT protocols, custom rule creation, long-term log retention, advanced querying, automated triage, playbook-driven response, automated containment, safety-oriented workflows for CNS/ATM, threat intelligence feeds, IOC detection, aviation and OT-specific threat intelligence, threat hunting, behavioural analytics, and incident case management. Log collection and integration capability (35 points) requires screenshots, connector catalogues, and integration guides for syslog, APIs, cloud connectors, agent-based/agentless collection, secure log forwarding, passive OT traffic analysis, and ticketing integration. Training (30 points) requires as-built documentation approach, user manuals, testing methodology and plan, training plan, knowledge transfer plan, and skills transfer approach. Failure to provide supporting evidence results in zero for that criterion.
Pricing Schedule
Source: Volume 1A - SOC.pdfPricing must be submitted on SBD 3.3 (Professional Services) and include all costs for the five-year period. The pricing schedule includes sections for Annual Licensing, Annual Managed Security, Support & Maintenance, Implementation, Administrator Training, and Response Training, with pricing required for each year of the five-year period and totals. Bids without a price or with incomplete pricing are non-responsive. Any budget amount indicated is a guide only; costing must be fair and reasonable. Offer must remain valid for 120 days from closing date.
Financial Requirements
Source: Volume 1A - SOC.pdf (RFP)Pricing must be submitted on SBD 3.3 (Professional Services) and include all costs for the five-year period, covering annual licensing, managed security, support and maintenance, implementation, administrator training, and response training. Bids without a price or with incomplete pricing are non-responsive. Budget indicated is a guide only; costing must be fair and reasonable. Offer valid for 120 days from closing date. Price evaluation uses the 80/20 preference point system (price 80 points).
Compliance Requirements
Source: Volume 1A - SOC.pdf (RFP)CSD registration: mandatory; submit proof of registration or application. SARS Tax Compliance Status PIN: must be valid for the full validity period; submit PIN or printed TCS. B-BBEE: valid certificate or sworn affidavit (for EMEs/QSEs) required to claim preference points. CIPC documents, shareholder certificates, and ID copies of shareholders required for specific goals. Declaration of Interest: complete and signed. SBD 1: Invitation to Bid must be completed and signed. Compulsory briefing session attendance required. Company experience: minimum 3 contactable reference letters for SOC implementation/management within last 5 years. Key personnel: at least 3 Tier-1 and 2 Tier-3 SOC Analysts with specified certifications (CISM, CEH, OSCP, GCIH, GCIA, Security+, vendor SIEM).
Health & Safety
Source: Volume 1A - SOC.pdfSafety is a core value: 'Safety and Customer Centricity: Prioritising customer needs and ensuring that safety is non-negotiable'. The SOC must include safety-oriented workflows for CNS/ATM systems. No specific OHS plan or HSE compliance documents are required beyond this.
Environmental
Source: Volume 1A - SOC.pdfThe document mentions 'economic, social, and environmental sustainability' as a general principle but provides no specific environmental requirements or sustainability criteria for this tender.
Contractual Terms
Source: Volume 1A - SOC.pdfATNS accepts no liability for accuracy of the brief; bidders rely on their own judgment. ATNS may vary scope and terms with written notice. Successful bidder must accept standard terms and conditions, including retention for non-satisfactory completion, breach, confidentiality, and professional indemnity insurance. ATNS may withdraw from commitments if circumstances dictate. All designs and documentation submitted are confidential. ATNS may reject, withdraw, or cancel any proposal, negotiate with one or more bidders, and is not obliged to accept the lowest bid. Contract concluded only when formal contract and SLA signed by both parties. ATNS may award one contract for all functions or multiple contracts. Bids may be rejected for proven corruption or fraud, abuse of SCM system, or failure to perform on previous contracts. Additional information may be requested; responses due within 7 working days. Bidders must keep bid information confidential. Copyright of documentation belongs to ATNS; no disclosure without written approval. Contractor must notify ATNS immediately if unable to deliver on time or at quoted price. On termination, bidder must hand over all documentation and deliverables without right of retention. Amendments must be in writing and signed. CSD registration mandatory before award. Proposals should be concise, in plain English, and follow prescribed format.
Section
Source: Volume 1A - SOC.pdfAdditional evaluation criteria: Functionality scoring per criterion: SIEM Functional Capability (35 points) - all 17 documents = 35, 13-16 = 28, 9-12 = 20, 5-8 = 12, no evidence = 0. Log Collection and Integration Capability (35 points) - all 8 requirements = 35, 6-7 = 26, 4-5 = 5, 2-3 = 9, 1 = 4, no evidence = 0. Training (30 points) - all 7 requirements = 30, 5-6 = 23, 3-4 = 15, 1-2 = 8, no evidence = 0. Minimum qualifying threshold for functionality is 70 points out of 100. Bidders scoring less than 70 will not be considered. Bidders scoring zero on any individual criterion will not be evaluated further. Bids not covering all required elements will be deemed non-responsive. Evaluation based strictly on information submitted; no assumptions made.
Sets the constitutional standard for fair, equitable, transparent, competitive and cost-effective public procurement.
Relevant because this is a South African public-sector procurement opportunity.
Act 5 of 2000
Covers preferential procurement and preference-point systems used in public tenders.
Relevant because this is a South African public-sector procurement opportunity.
Act 12 of 2004
Supports anti-corruption controls and supplier integrity in procurement processes.
Relevant because this is a South African public-sector procurement opportunity.
Act 28 of 2024
Provides the national framework for public procurement across government.
Relevant because this is a South African public-sector procurement opportunity.
Act 2 of 2000
Supports access to tender records, award decisions and public-sector procurement information.
Relevant because this is a South African public-sector procurement opportunity.
Act 3 of 2000
Supports lawful, reasonable and procedurally fair administrative tender decisions.
Relevant because this is a South African public-sector procurement opportunity.
Address
ATNS Company Limited, Eastgate Office Park, Block C, - Bruma - Johannesburg - 2298
Source confidence
High source confidence
Official source
eTenders.gov.za
Documents found
1
Last checked
29 Aug 2026
AI status
Enhanced
Data conflicts
None detected
This tender has strong source evidence, including source metadata and supporting tender information synced from the government tender portal.
Tenders SA is not the issuing authority. All tenders are automatically synced from the official government tender portal. Always confirm final submission details, closing dates, briefing sessions, eligibility requirements, and documents on the official government portal before applying.
Learn how to submit a winning bid with these related articles
Win consulting, legal, accounting, and engineering service contracts with government. Learn registration requirements and proposal strategies.
Win government insurance, banking, actuarial, and financial consulting contracts. FSCA licensing requirements and tender strategies for financial service providers.
Master the art of the consulting bid. How to structure your methodology, price your services competitively, and score maximum evaluation points.
A professional guide for law firms to join the provincial and municipal legal panels in Gauteng, covering compliance, specialization, and bidding.
💡 Want more tendering tips and strategies?
Explore Our BlogGet deep intelligence on Information service activities. Unlock full pricing strategies, bid frequency, and historical win rates.