Broad-Based Black Economic Empowerment Act (B-BBEE Act)
Act 53 of 2003
Provides the empowerment-compliance context often used in public-sector supplier evaluation.
Relevant because this is a South African public-sector procurement opportunity.
Issuing Organization
Export Credit Insurance Corporation of South Africa LimitedLocation
Gauteng
Closing Date
06 Oct 2026
Documents available on tender detail page
Tender Type
Request for Proposal
Delivery Location
Byls Bridge Office Park, Building 9, 4th floor, 11 Byls Bridge Boulevard, - Centurion - Pretoria - 0186
Organization Type
GOVERNMENT
Published
11 Sept 2026
OCDS Reference
ocds-9t57fa-169960
The export credit insurance corporation of south africa (soc) limited (ecic) invites proposals for the provision of cybersecurity managed services and licenses for a period of three years. The successful bidder will deliver managed cybersecurity services, including two annual in-person interactive awareness sessions (one for staff in october/november and one for management on a date to be confirmed), and must quote for a total of 260 hours per year. The tool must be cloud-based and not require ecic to provide infrastructure such as servers. Only the license subscriptions specified under the scope of work must be quoted for. The contract may be terminated by ecic with not less than 90 days' prior written notice. The evaluation follows three phases: phase one (compliance), phase two (functionality, with a minimum threshold as indicated in paragraph 12.4 And an overall minimum score of 75), and phase three (80/20 preference point system). Bidders must submit evidence for third-party risk assessment and provide documentation for specific goals claims. Ecic will not award to bidders restricted from doing business with the state, in the employ of the state without permission, or with undisclosed business interests. Tax compliance is required. Bidders may not subcontract more than 25% of the contract value to an enterprise that does not qualify for the same points, unless the subcontractor is black owned, black women owned, black youth owned, or owned by black persons with disabilities. Ecic may award to more than one bidder, may not accept the lowest price, and may declare the bid closed if NO proposal is accepted. Enquiries must be in writing only and must reference specific paragraph numbers. Electronic submissions must be in pdf, under 20mb (or split if larger), and submitted before the closing date and time. The validity period is as stated in the bid; if a bidder does not agree to extend, ecic will stop evaluating. All dates and times are south african standard time. Ecic will process bidders' personal information for evaluation purposes, and by submitting a proposal, bidders consent to this processing.
Continue with tenders sharing this issuer, category, or province.
Return to this tender’s issuing organisation, province, or category.
Continue with tenders sharing this issuer, category, or province.
Bidders must provide evidence and documentation when responding to the Third-Party Risk assessment; if information is obtainable from Microsoft Partner Portal, ECIC may use it as if submitted by the bidder.
Bidders must achieve the minimum threshold indicated in paragraph 12.4 and an overall minimum score of 75 in the functionality evaluation to proceed to Phase Three.
Bidders must complete the SBD6.1 Form and indicate, in one block, the number of Specific Goals points claimed; failure to do so results in zero points for Specific Goals.
Bidders must submit the document required to substantiate Specific Goals claims together with the SBD6.1 Form; otherwise the bid may be disqualified.
Bidders must not subcontract more than 25% of the contract value to an enterprise that does not qualify for at least the same points, unless the subcontractor is Black Owned, Black Women Owned, Black Youth Owned, or owned by Black persons with disabilities.
Bidders must not be restricted from conducting business with the State, must not be in the employ of the State without permission, and must declare any business interests as required; ECIC will verify with relevant Organs of State.
Bidders must submit their proposal electronically in PDF format, under 20MB (or split into parts if larger), before the closing date and time; all enquiries must be in writing and reference specific paragraph numbers.
Date & Time
Tuesday, 06 October 2026 - 11:00
Venue
null
None
Categories
Request for Proposal
Byls Bridge Office Park, Building 9, 4th floor, 11 Byls Bridge Boulevard, - Centurion - Pretoria - 0186
Tenders in this industry often require registration with these bodies.
Recommended Certifications
Having these can improve your winning chances: IITPSA Membership, ISO 27001 (Information Security Management), ISO 20000 (IT Service Management), CISSP
AI Document Analysis Stages
Description
Source: ECIC05P-2026_27.pdf11 Sept
2026
Tender Published
Tender was published
06 Oct
2026
Closing Date
Tender closing date
These references help suppliers understand the public-procurement framework around this opportunity. They are generated from the tender category, issuing organisation type and procurement context.
These rules commonly apply to South African public-sector procurement.
Act 53 of 2003
Provides the empowerment-compliance context often used in public-sector supplier evaluation.
Relevant because this is a South African public-sector procurement opportunity.
Act 108 of 1996 (s217)
This is general procurement context, not legal advice. Always verify requirements in the official tender documents and issuing authority notices.
ECIC05P-2026_27.pdf
The Export Credit Insurance Corporation of South Africa (ECIC) seeks a service provider to deliver managed cybersecurity services and licenses for three years, including Microsoft 365 security, endpoint security, cloud backup, vulnerability management, DMARC, cybersecurity awareness, and ISO27001:2022 and COBIT 2019 assessments.
To download these documents and access AI-powered analysis, visit the main tender page.
Matched by category & region
Free guidance to prepare before you bid
Not sure if your business is ready for this tender? Check CSD, CIDB, and B-BBEE requirements, run a readiness assessment, and move from opportunity to submission.
Open Supplier Readiness HubMedian Estimate
R 2 835 682
Range
Based on 25 comparable awarded tenders. Companies with similar profiles typically bid near the median.
* Estimates are based on historical data and do not guarantee actual award values.
We refine every tender document through these stages so you can brief your team and prepare your bid with confidence. Anything marked as "in progress" will be upgraded automatically — no action required from you.
The mandate of ECIC is to facilitate and encourage South African export trade by underwriting export credit loans and investments outside the country, enabling South African contractors to win capital goods and services contracts abroad. This tender is for cybersecurity managed services and licenses for a three-year period.
Important Dates
Source: ECIC05P-2026_27.pdf (RFP){"closingDate":"6 OCTOBER 2026","closingTime":"11H00","briefingSession":"{"date":null,"time":null,"venue":"ion .................................................................................................................. 10","is_compulsory":false}"}
Contact Information
Source: ECIC05P-2026_27.pdf (RFP){"name":"Mr. S Mayekiso","email":"[email protected]","phone":null,"department":null,"address":"SES FOR A PERIOD OF THREE"}
Evaluation Criteria
Source: ECIC05P-2026_27.pdf (RFP)Must be registered on National Treasury Central Supplier Database (CSD). Must submit completed and signed SBD 1, SBD 4, and SBD 6.1 forms. Must provide proof of Microsoft partnership and partnership for proposed DMARC and vulnerability tools. Must provide CVs and certifications for assessment resources (ISO27001 lead auditor/implementer and COBIT 2019 Design and Implementation, 3+ years' experience). Must provide contactable reference letters on company letterhead (not older than 5 years). Must not be restricted from doing business with the state, and tax affairs must be compliant. Bidders claiming Specific Goals must submit a valid B-BBEE certificate or sworn affidavit. Bidders must complete a Third-Party Risk Assessment if appointed.
Technical Specifications
Source: ECIC05P-2026_27.pdf (RFP)Contents
A. Introduction to the request for proposal (RFP) ........................................ 3
Introduction ....................................................................................................................... 3
Purpose .............................................................................................................................. 3
Background ....................................................................................................................... 3
Procurement Regulations ................................................................................................. 4
B. Terms of reference ................................................................................................... 5
Scope of services .............................................................................................................. 5
Service level agreement .................................................................................................... 7
Billing structure ................................................................................................................. 8
Delivery address ................................................................................................................ 8
Bid/contract conditions .................................................................................................... 9
Due diligence/site inspection ......................................................................................... 10
Bid evaluation .................................................................................................................. 10
Evaluation Phase Two: Functional ................................................................................ 12
Phase Three: Preference point system ......................................................................... 17
Document(s) required to substantiate claims for Specific Goals ............................... 18
Phase Four: Objective criteria ........................................................................................ 18
Standard bidding documents ......................................................................................... 19
Instructions to respondents ........................................................................................... 19
Timeline of the bid process ............................................................................................ 21
Bid rules ........................................................................................................................... 22
Annexes ................................................................................................................................. 26
Annexure A: Protection of personal information .................................................................. 26
Annexure B: Format for fee proposal (Pricing Example) ..................................................... 28
Applicable standard bidding documents ............................................................... 29
Sbd 1 ........................................................................................................................................ 29
Sbd 4 ........................................................................................................................................ 31
Sbd 6.1 ..................................................................................................................................... 35
Checklist ................................................................................................................................... 41
P a g e 2 | 42
Request for proposal: cybersecurity managed services and licenses
For a period of three years
A. Introduction to the request for proposal (RFP)
1.1. The Export Credit Insurance Corporation of South Africa (SOC) Limited1 (ECIC or
Corporation) is a self-sustained state-owned entity listed under Schedule 3B of the Public
Finance Management Act (as amended) and established in terms of the Export
Credit and Foreign Investments Insurance Act (as amended).
1.2. The mandate of ECIC is to facilitate and encourage South African export trade, by
underwriting export credit loans and investments outside the country, to enable South
African contractors to win capital goods and services contracts in countries outside South
Africa. ECIC is a registered Financial Service Provider and is regulated by the Financial
Sector Conduct Authority and Prudential Authority (FSP No: 30656). Currently exempted
in terms of FAIS Notice .
1.3. ECIC operates at the following address:
Byls Bridge Office Park
Building 9, Fourth Floor
11 Byls Bridge Boulevard
Highveld Extension 73
Centurion
0157
2.1. The purpose of this Request for Proposal (RFP) is to appoint a service provider to
provide Managed Security Services, including conducting ISO27001:2022 and
COBIT2019 follow-up assessments, for a period of three (3) years.
3.1. The ECIC operates on a hybrid sourcing model for ICT comprising internal resources and
leveraging skills and competencies through outsourced services. The outsourced
services in the area of ICT Governance and Information Security are a critical strategic
position to ensure the ECIC have access to specialised skills as and when a need arises
for proactive and reactive support.
3.2. ECIC subscribes to the Corporate Governance of ICT Policy Framework, COBIT 2019
and ISO 27001 as guidelines for the implementation of ICT Governance and Information
Security Management within the Corporation, which is supported by the ISO27001:2022
and COBIT2019 assessments conducted every two years to determine the capability
maturity level of the Corporation.
3.3. The high-level summary of the current ECIC technology environment in line with the
required services:
3.3.1. KnowBe4.
1 Further information on the ECIC can be found at www.ecic.co.za
P a g e 3 | 42
Request for proposal: cybersecurity managed services and licenses
For a period of three years
3.3.2. Windows server environment (5 servers, which may grow to 7 servers).
3.3.3. Microsoft 365 E3.
3.3.4. Kaspersky EDR.
3.3.5. N-Able Cove backup.
3.3.6. 100 end users expected to grow to 120 users.
3.3.7. Internal Security personnel responsible for coordinating and managing the MSS
provider.
3.4. ECIC has its own licenses for the technologies mentioned above. Only the license
subscriptions specified under the scope of work must be quoted for
4.1. This bid is subject to the Preferential Procurement Policy Framework Act No.
and the Preferential Procurement Regulations, 2022, the General Conditions of Contract
(GCC) and, if applicable, any other special conditions of contract. Where, however, the
special conditions of contract conflict with the general conditions of contract, the special
conditions of contract prevail.
P a g e 4 | 42
Request for proposal: cybersecurity managed services and licenses
For a period of three years
B. Terms of reference
5.1. The successful bidder will be required to provide the following Cybersecurity Services:
5.1.1. Microsoft 365 security services
5.1.1.1. Monitor and conduct regular security health checks of the Microsoft
365 environment, make recommendations, and assist with the
implementation of remediations.
5.1.1.2. Assist with the implementation of CIS Baselines on both the Microsoft
environment and the hosted Windows Server environment.
5.1.1.3. Provide monthly reports on the security posture of the environment.
5.1.2. Endpoint security services
5.1.2.1. Monitor and conduct regular health checks of
the endpoints based on the current Kaspersky endpoint protection
solution.
5.1.2.2. Assist with optimising the configuration and testing of the
environment, including security dashboards and reports.
5.1.2.3. Provide monthly reports on the security posture of the environment.
5.1.3. Cloud backup services (N-Able Cove)
5.1.3.1. Monitor and conduct regular health checks of cloud backups based on
the N-Able Cove solution.
5.1.3.2. Assist with optimising the configuration and testing of the environment,
including dashboards and reports.
5.1.3.3. Provide monthly reports on the health and performance of
the backup environment.
5.1.4. Vulnerability Management
5.1.4.1. Provide an online tool for prompt remediation of vulnerabilities such as
Tenable Nessus or equivalent. The tool must not require the ECIC to
provide infrastructure such as servers. The tool must be an online tool
with the capability to monitor ECIC devices on premises, at a private
cloud hosting location and in various locations when users work
remotely.
5.1.4.2. Provide monthly reports with age analysis for remediation of
vulnerabilities with different classifications (Critical, High, Medium,
Low, etc).
P a g e 5 | 42
Request for proposal: cybersecurity managed services and licenses
For a period of three years
5.1.4.3. Provide a tool that automates vulnerability management and the
Executive Age Summary reporting capabilities to reduce dependency
on manual effort and human-driven reporting processes to calculate
vulnerability age analysis.
5.1.5. DMARC (Domain-based Message Authentication, Reporting and
Conformance) Analyser
5.1.5.1. Provide, configure, and support DMARC analyser for the ECIC domain
(@ecic.co.za). The ECIC does not have DMARC implemented and
intends to implement it to mitigate the risk of domain impersonation/
spoofing and provide monthly reports.
5.1.5.2. The DMARC analyser subscription must be for three years and
registered under the ECIC’s account.
5.1.6. Cybersecurity Awareness
5.1.6.1. Provide two annual interactive cybersecurity awareness sessions, one
for staff (October/November) and the other for Management (Date to
be confirmed), and the sessions must be in person. The staff session
is to be arranged as a Cyber Day in person.
5.1.6.2. Provide quarterly phishing simulations leading up to each of the
interactive cybersecurity awareness sessions.
5.1.6.3. Assist with strategic advisory based on insights from the KnowBe4
platform and monthly reporting to ensure effective and measurable
cyber-awareness training.
5.1.7. ISO27001:2022 Assessment (Years 1 and 3 – Once Off)
5.1.7.1. Assess the Corporation’s information security controls based on the
ISO27001:2022 framework.
5.1.7.2. Provide a report of the detailed findings and recommendations for
improving the compliance level of the Corporation.
5.1.7.3. Assist with remediation of ISO27001 findings, which may include
expert advice and/or updating and developing certain documentation
such as plans, framework and policies.
5.1.8. COBIT 2019 Assessment (Year 2 – Once Off)
5.1.8.1. Conduct the ICT governance maturity for the Corporation based on
the COBIT 2019 framework.
5.1.8.2. Provide a report of the detailed findings and recommendations for
improving the maturity level of the Corporation.
P a g e 6 | 42
Request for proposal: cybersecurity managed services and licenses
For a period of three years
5.1.8.3. Assist with remediation of COBIT2019 findings, which may include
expert advice and/or updating and developing certain documentation
such as plans, framework and policies.
5.1.9. Skills transfer and knowledge sharing:
5.1.9.1. Provide skills transfer and knowledge sharing plan outlining how the
ECIC ICT personnel (up to 3 personnel) will be equipped with practical
skills and knowledge to perform basic support of the technology
solutions provided and/or supported by the bidder as part of this
tender. The skills transfer will include at least configuration and
technical support-related aspects.
6.1. The bidder must have adequate team capacity to provide continuous support to the ECIC.
The support structure must ensure business continuity by avoiding dependency on a
single resource and maintaining sufficient backup capabilities. The bidder shall provide
security-related proactive and reactive support services throughout the contract period.
6.2. The ECIC-authorised ICT personnel (up to 3 personnel) must have access to the tools
provided and supported by the bidder. The access is for pulling ad hoc reports and
performing basic support functions.
6.3. The bidder must be able to log support calls directly with the OEM on behalf of the ECIC
for all technology solutions supported and provided for under the scope of work.
6.4. The bidder must provide an established technical support process with an electronic
helpdesk system and a defined Service Level Agreement (SLA) matrix for attending to
and resolving queries. The bidder will need to align their SLA matrix with the commitment
and measurement of the below matric. to provide consistent service, support and delivery:
6.4.1. Target Time to Action (TTA): The maximum allowable to acknowledge ticket and
must begin active work or intervention on the query logged.
6.4.2. Mean Time to Resolution/Repair (MTTR): Measures the average time it takes to
resolve an incident once it's been identified.
6.4.3. Severity and Priority:
6.4.3.1. Severity 1: Outage or unavailability of service or functionality affecting
business continuity.
6.4.3.2. Severity 2: Major disruptions to a significant business service or
system but isn't as devastating as a severity 1.
6.4.3.3. Severity 3: Moderate effect on ECIC operations; usually affecting non-
critical functionalities within core systems, however, significantly
hinders business productivity.
6.4.3.4. Severity 4: Represents a low-priority issue that causes minimal or no
disruption to normal service.
P a g e 7 | 42
Request for proposal: cybersecurity managed services and licenses
For a period of three years
NOTE: A detailed SLA will be discussed and agreed on during the contractual stage.
Table 1
Severity Target Time to action (TTA) Mean Time to
Resolution/Repair
(Mttr)
Severity Target Time to action Mean Time to
(TTA) Resolution/Repair
(Mttr)
Severity 1 – Critical 15 min 2 hours
Severity 2 - High 30 min 4 hours
Severity 3 – Medium 1 hour 8 hours
Severity 4 – low 4 hours 24 hours
7.1. The managed services contract will be billable across two components as follows:
7.1.1. Monthly retainer:
7.1.1.1. 16 hours monthly allocated towards weekly health checks and
security posture reporting for in-scope services such as Microsoft
services, endpoint security services, vulnerability management, cloud
backup services, DMARC and cybersecurity awareness.
7.1.1.2. Unused hours will not be utilised beyond the contract end date.
7.1.2. Bucket of support hours:
7.1.2.1. Usable towards any of the in-scope service areas. The work may
include advisory-related services, technical support and
implementation.
7.1.2.2. Billable on a time and materials basis – estimated hours for each
assignment must be formally communicated and/or approved by the
ECIC before the work is conducted.
7.1.2.3. A total of 260 hours per year must be quoted for.
7.1.2.4. Unused hours will not be utilised beyond the contract end date (except
for the hours already committed).
8.1. The implementation and support can be provided remotely; however, where necessary,
a representative of the service provider may be required to be at the ECIC office at the
following address:
Byls Bridge Office Park
Building 9, Fourth Floor
11 Byls Bridge Boulevard
P a g e 8 | 42
Request for proposal: cybersecurity managed services and licenses
For a period of three years
Highveld Extension 73
Centurion
0157
9.1. The following condition of contract applies to this bid:
9.1.1. Governance compliance:
9.1.1.1. The appointed bidder will be subjected to completing a Third-Party
Risk Assessment to demonstrate the level of security, governance,
compliance and industry standards the bidder conforms to.
9.1.1.2. The bidder must provide evidence and documentation when
responding to the Third-Party Risk assessment.
9.1.1.3. The bidder must indicate which industry standards are currently being
used in their organisation to manage and implement the tools and
services mentioned in the scope of work.
9.1.2. Bidder accreditations:
9.1.2.1. The bidder must provide proof that they are an authorised partner of
Microsoft; valid proof of partnership such as a letter or certificate or
any other valid proof such as confirmation from the Microsoft partner
portal must be provided. ECIC will verify the information provided on
the Microsoft Partner Portal. If a bidder did not provide the information,
but such information can be obtained from Microsoft Partner Portal,
ECIC will use such information as if it was submitted by the identified
bidder.
9.1.2.2. The bidder must provide proof that they are an authorised partner of
the DMARC and Vulnerability tools proposed.
9.1.3. Bidders' team capacity to conduct assessments: Security and Governance
Assessments:
9.1.3.1. The bidder must provide copies of Curriculum Vitae(s) and
certifications of at least one resource who will conduct the
assessments for ISO27001:2022 or latest and COBIT 2019 or latest.
The resource(s) must be certified as an ISO27001 lead auditor/
implementer and COBIT 2019 Design and Implementation with at least
3 years' experience.
9.1.4. Contactable references
9.1.4.1. The bidder must provide contactable reference letters for previous
Managed Cybersecurity Services and Independent Assessments
(ISO27001 and COBIT2019) projects. If only a list of references was
provided for functional evaluation criteria 1.1 and 1.2. The reference
letters and/or project delivery date must not be older than five years
P a g e 9 | 42
Request for proposal: cybersecurity managed services and licenses
For a period of three years
from the closing date of this bid. Reference letters must be on a
company letterhead.
ECIC will not appoint a bidder who fails to provide all the information required under
paragraph 9.1.
9.2. The successful bidder must sign a confidentiality undertaking as part of the service level
agreement.
9.3. The agreement may be terminated by the ECIC if it has reasonable grounds to do so,
with not less than 90 days’ prior written notice. A termination clause will form part of the
agreement and may include events such as unsatisfactory performance, defining events,
departure of key personnel, governance and ownership issues and reputational risks.
10.1. At the ECIC’s discretion, a due diligence and/or site inspection may be conducted on the
identified bidder. ECIC will visit the identified bidders’ premises or bidder’s client (with
permission from the bidder) with the objective of verifying information as contained in their
respective bid documents.
10.2. Where applicable, the ECIC will issue criteria for the due diligence review or site
inspection beforehand to the applicable bidder(s). Should it be discovered during a due
diligence visit or site inspection that the information submitted by the identified bidder is
inconsistent with what is on their current premises of business, ECIC reserves the right
to disqualify such bidder.
10.3. ECIC may identify another bidder using the next highest points obtained in the evaluation
phase as stipulated in paragraph 11.1.3, taking into consideration the process followed
under paragraphs 10.1 and 10.2.
11.1. The proposals will be evaluated in phases as highlighted below and detailed in
paragraphs 11.1.1 and 11.1.4 of this document:
11.1.1. Phase One: Compliance
Compliance with the requirements of this bid in this evaluation phase, all bidders
that fail to provide the required information and documentation will be disqualified
from further evaluation.
11.1.2. Phase Two: Functional evaluation
In this evaluation phase, bidders are expected to obtain a minimum of 75 out of
100 points to proceed to the next evaluation stage of the evaluation. Regardless
of whether the overall minimum score of 75 is achieved, bidders must also
achieve the minimum threshold as indicated in paragraph 12.4. Failure to obtain
the prescribed minimum points will automatically disqualify the bid offer from
proceeding to the next evaluation phase.
P a g e 10 | 42
Request for proposal: cybersecurity managed services and licenses
For a period of three years
11.1.3. Phase Three: Preference point system
The 80/20 preference point system shall be applicable to this phase, where 80
points represent maximum obtainable points for the lowest acceptable bid and 20
points represents maximum obtainable points for Specific Goals. Points will be
awarded to a bidder for attaining the Specific Goals in accordance with the table
as listed in the bid documentation (refer to paragraph 13, read together with the
table in (paragraph 4.1).
11.1.4. Evaluation Phase Four: Objective criteria
ECIC will apply objective criteria as detailed in paragraph 15.
P a g e 11 | 42
35 points
20 15 Sub- Points
Rating
0 1 2 3 4 5 0 1 2 3 Factor
(1 x
provided. and provided. references provided provided provided provided. vice-versa). provided. 1
or ISO27001). ISO27001).ALLOCATION x
or 1 references references reference reference references references references contactable COBIT2019 provided. provided. andPOINTS x five assessments
OF 2 COBIT2019 contactable contactable contactable contactable contactable contactable contactable references least references COBIT2019 No One Two Three Four At provided. No One (Either Two x Three (Either ISO27001DESCRIPTION DETAILS/INFORMATION 1.1.1. 1.1.2. 1.1.3. 1.1.4. 1.1.5. 1.1.6. 1.2.1. 1.2.2. 1.2.3. 1.2.4.
from Services Managed provided. delivery from letters details, the project was they delivery the Reference contactable contactable letters years where the project award. where years of Assessments: project 5 were project five Reference contact the than letterhead. letterhead. bid. provide where provide bid. DESCRIPTION Reference delivered, included. letters) than and/or year and/or assessments. older this be condition older this letters) Services of provided, organisation a COBIT2019 must Cybersecurity must be company is and (list/ be of company letters (list/ letters not date the was must be and similar not a CRITERIA a list on date on a of will bidder bidder be be must must closing Managed experience: The references Cybersecurity Reference date the must Where name project description delivered letters ISO27001 The references conducted Reference date closing must EVALUATION 1.2. 1.1.
letters
Contactable reference EVALUATION CRITERIA 1.
15 35 points
10 10 Sub- Points
3 5 3 5 3 rating
4 5 0 to to 0 to to 0 to Factor 1 4 1 4 1
(A x
2 all vice- lacks in- the with does noor the with at all clearly or and and and in-scope in-scope or provided references COBIT2019 vague, the vice-versa). all experience vague not required qualifications
x provided covers is the is or 3 of provided of provided. vague ofALLOCATION CV CV not requirements CV provided. is relevant qualifications qualifications assessments some COBIT2019 or is references covered copies of it x contactable not of the details the proposal with lack but or 2POINTS minimum requirements and CV assessments five copies minimum qualifications copies (AOF of provided ISO27001 of components. the clearly x proposal detailed however, contactable however, least 2 proposals not meet qualifications Four minimum ISO27001 At provided and versa). The components, The components details. The scope Either or Provided CV; minimum indicated. CV experience provided. CV not copies Provided CV;DESCRIPTION DETAILS/INFORMATION 1.2.5. 1.2.6. 2.1.1. 2.1.2. 2.1.3. 3.1.1. 3.1.2. 3.1.3. 3.2.1. 3.2.2.
at
senior in of with least must details, the project was proposal the services or be following project 5 including be history must Reference equivalent. at of CV lead/ the manager management Management where project award each or of contact of CV with The detailed the scope one a meet project applicable qualification. technical employment experience, suite. DESCRIPTION delivered, included. will the a The year least a (Project project be submit of at manager provided, organisation condition of other they a under and provide relevant security role. by conditions. Security/Cybersecurity CV is the was CV must be must CRITERIA list how a PMP Professional). Prince2. Any management Project years experience. a of will a must years' 365
7 bidder contract CV Where name project description delivered letters The outlining requirements and Provide equivalent accompanied certifications: Provide engineer/consultant/architect The Information least Microsoft EVALUATION 2.1. 3.1. 3.2.
Services team
Cybersecurity Managed proposal Bidder’s capacity EVALUATION CRITERIA 2. 3.
Points
15 Sub- Points
5 3 5 rating
to 0 to to Factor 4 1 4
of or clearly required CVs minimum of of two with clearly indicating and not copies vague, not qualifications copies qualifications the is of experience clearly provided; meet no minimumALLOCATION CV
a
not or the details copies CVs CVs relevant and two required two provided. relevantPOINTS requirements and of do requirements of
OF of clearly however, minimum minimum minimum minimum indicated. CV experience provided. A provided requirements qualifications Provided qualifications CVs; minimum indicated. A the copies provided.DESCRIPTION DETAILS/INFORMATION 3.2.3. 3.3.1. 3.3.2. 3.3.3.
the must in of listed of two
Cove two Systems Systems Security security the authorised technical in suite, M365 or least include vulnerability an two experience experience at least certification. product resources of at by Hacker). equivalent, N-Able equivalent: may from least of 27001). information two
or DESCRIPTION or Information Information Information Certification. at as and years combined Ethical of security The 5 coupled copies international EDR with such (ISO/IEC by Security+. Security applicable least body. CVs (Certified Professional). certification transcript (Certified (Certified or CRITERIA at qualifications/certifications M365 certifications (Certified other of CISSP. CEH. ISO27001. CISA. CISM. CISSP Security CEH ISO27001 CISA Auditor). CISM Manager). CompTIA Microsoft Any qualification/ Provide resources the Kaspersky backups equivalent, management. have cybersecurity the below: accompanied following Proof certificate certification 3.3. EVALUATION
13.1. The formula below will be used to calculate the lowest acceptable bid price:
=
Where
Ps = Points scored for price of tender under consideration;
Pt = Comparative price of bid or offer under consideration; and
Pmin = Price of the lowest acceptable tender.
13.2. Depending on the bidder’s level of Specific Goals, a maximum of 20 Specific Goals
points may be awarded to a bidder. The points scored by a bidder for Specific Goals
will be added to the points allocated for price.
13.3. The table below reflects the number of points to be allocated to a bidder for Specific
Goals:
Table 3
Number of
points
The specific goals allocated points in terms of this tender
allocated
(80/20 system)
B-BBEE Procurement Recognition Level of 135% and at least
50.1% ownership by (or combination thereof):
a. Black people, or
b. Black female, or
c. Black Designated Group, or
d. Black Voting Rights.
B-BBEE Procurement Recognition Level of at least 110% and
at least 30% ownership by (or combination thereof):
a. Black people, or
b. Black female, or
c. Black Designated Group, or
d. Black Voting Rights.
B-BBEE Procurement Recognition Level of at least 110% and
up to 30% ownership by (or combination thereof):
a. Black people, or 5
b. Black female, or
c. Black Designated Group, or
d. Black Voting Rights.
Any other B-BBEE Procurement Recognition Level up to 110%. 0
[Bidders are required to indicate, in one block, the number of
Points they are claiming for specific goals in the table in
(Paragraph 4.1). In the event where a bidder makes a
P a g e 17 | 42
Request for proposal: cybersecurity managed services and licenses
For a period of three years
Mark (one mark), ecic will consider the corresponding points
To be the one which the bidder is claiming for. Where a bidder
Makes multiple marks or does not make any mark or indication
At all in the table, the bidder will be allocated zero (0) points
For specific goals, notwithstanding evidence provided.]
13.4. The total points achieved under this evaluation criterion will be rounded to the
nearest two decimal places.
14.1. For this bid, bidders are requested to provide the following documents in
substantiation for their claim of Specific Goals in line with the 2022 Preferential
Procurement Regulations:
Table 4
Specific Goals Document required to substantiate the Specific Goals
claim
B-BBEE Procurement Copy of a valid B-BBEE Certificate or Copy of a valid
Recognition Level Sworn Affidavit
14.2. Any bid received from a bidder who did not provide the document requested in this
paragraph 14 and do not indicate the number of Specific Goals they are claiming for
in the SBD6.1 Form, in the table on (paragraph 4.1) shall be awarded
zero points for Specific Goals (i.e. both the document required to substantiate the
Specific Goals Claimed and the SBD6.1 must be submitted with the response to this
bid).
14.3. Points for Specific Goals will be allocated as indicated in paragraph 13 of this RFP
and in the SBD 6.1 Form. Bidders are required to indicate how they claim points for
each preference point on the SBD6.1 Form, in the table on (paragraph
4.1). In the event that a bidder does not indicate the preference points they are
claiming, the bidder will be awarded zero (0) points for Specific Goals.
15.1. In this evaluation stage, ECIC will check if the bidder has a person who meets the
following criteria in awarding the bid:
15.1.1. The bidder has a significant shareholder or owner (or equivalent) (directly
or indirectly) who is classified or can be classified as a Prominent Influential
Person (PIP) in accordance with the Financial Intelligence Centre Act, (FICA).
15.1.2. The bidder has a shareholder or member or owner or director (or
equivalent) who has questionable integrity status.
15.1.3. The bidder has a director or equivalent who is classified or can be classified
as a PIP in accordance with FICA.
P a g e 18 | 42
Request for proposal: cybersecurity managed services and licenses
For a period of three years
15.2. Should it be found during this evaluation stage that the bidder who has attained the
highest points under Evaluation Stage Four (Preference Point System) has persons
listed in paragraphs 15.1.1 to 15.1.3, ECIC reserves the right to conduct further due
diligence on the person(s). Should the outcome of further due diligence not be
satisfactory to ECIC, or if such a person(s) poses an unacceptable high risk
reputation and/or integrity of the person(s) be questionable, ECIC reserves the right
not to award the bid to that bidder. This process may be repeated for the next bidder
if so required.
16.1. Bidders are required to complete and attach the following Standard Bidding
Documents:
Table 5
Reference
Details
Number
Invitation to bid SBD 1
Declaration of Interest SBD 4
Preference Points Claim Form for Preferential Procurement
Regulations 2022
Sbd 6.1
Should a bidder not complete and sign the SBD6.1, the
bidder will be allocated 0.00 points for Specific Goals.
16.2. ECIC will not award a bid to a bidder who has not submitted complete and signed
Standard Bidding Documents, and the Standard Bidding Documents forms part of
the condition of award.
17.1. Correspondence
17.1.1. No telephonic or any other form of communication with any other ECIC
member of staff other than the named individual below, relating to this RFP,
will be permitted. All enquiries must be in writing only.
17.1.2. All questions relating to the contents of the tender (conditions, rules, terms
of reference, etc.) must be forwarded in writing via email to
[email protected] by not later than Monday, 21 September 2026.
Questions received after this date will not be entertained.
17.1.3. All questions must reference specific paragraph numbers, where
applicable.
17.1.4. All enquiries (received on or before the closing date for enquiries) will be
consolidated, and ECIC will publish one response document on the ECIC
P a g e 19 | 42
Request for proposal: cybersecurity managed services and licenses
For a period of three years
website (www.ecic.co.za) within three working days after the date indicated
in paragraph 17.1.2, on or before Friday, 25 September 2026.
17.1.5. No requests for information shall be made to any other person or place,
and in particular not to the existing provider of this service.
17.2. Submission of the proposals
17.2.1. Bid documents must be clearly marked for ease of reference and be
submitted in PDF format on/or before the closing date and time to the
following email address:
17.2.2. The following email submission procedures or protocols must be adhered
to ensure safe and secure submission of the tender documents and
supporting documents:
17.2.2.1. The tender document, including the supporting or returnable
documents, should be submitted via email in PDF format.
17.2.2.2. If the PDF tender document, including the supporting or
returnable documents, is less than 20 Megabytes (MB), it should
be submitted as one document. If the electronic bid document is
more than 20MB, the electronic tender document should be split
in order to adhere to the 20MB email capacity.
17.2.2.3. Bidders are also encouraged to submit a USB detailing their
tender proposals.
17.2.3. In the event that bidders are experiencing challenges with emailing
documents, tenders can be hand-delivered at the ECIC Offices on/or before
the closing date and time at:
Byls Bridge Office Park
Building 9, Fourth Floor
11 Byls Bridge Boulevard
Highveld Extension 73
Centurion
0157
17.2.4. Any proposal received after the closing date and time will not be
accepted.
17.2.5. All proposals and all subsequent information received from respondents will
not be returned. The proposals should be addressed to the Head of
Procurement of ECIC.
P a g e 20 | 42
Request for proposal: cybersecurity managed services and licenses
For a period of three years
18.1. The period of validity of the tender and the withdrawal of offers, after the closing date
and time, is 90 days, expiring on Monday, 04 January 2027. If there is a need to
extend the bid validity period, ECIC will request, in writing, permission to extend the
validity period from all bidders before the expiry of the current validity period.
18.2. After the due date for response from bidders on the request to extend the validity
period, ECIC will assume that all bidders have agreed to the request to extend and
continue evaluating all bids received at the closing date and time as received on the
closing date and time. Any award will be on the quoted bid amount as indicated in
the proposal as at the closing date and time of the bid. If a bidder does not agree to
extend the validity period on the original terms (as at the closing date of the bid),
ECIC will stop evaluating the proposal received from such bidder.
18.3. The project timeframes of this bid are set out below:
Table 6
Stage description of stage estimated completion
Date (or work week
Ending)
Advertisement of bid on the
Website
Questions relating to the bid from the
bidder(s)
Response to the questions from the
bidders
Bid closing Tuesday, 06 October 2026
Compliance Evaluation Friday, 16 October 2026
Functional Evaluation Friday, 23 October 2026
Preference Points Friday, 30 October 2026
Bid Adjudication Friday, 06 November 2026
18.4. All dates and times in this bid are in South African Standard Time.
18.5. Any time or date in this bid is subject to change at the discretion of ECIC. The
establishment of a time or date in this bid does not create an obligation on the part
of ECIC to take any action or create any right in any way for any bidder to demand
that any action be taken on the date established. The bidder accepts that, if ECIC
extends the deadline for bid submission (the Closing Date) for any reason, the
requirements of this bid otherwise apply equally to the extended deadline.
18.6. ECIC will notify all bidders of the outcome of the bid within 30 days from the date of
acceptance of bid by the identified bidder.
P a g e 21 | 42
Request for proposal: cybersecurity managed services and licenses
For a period of three years
19.1. Awarding a bid
19.1.1. ECIC will not award a bid to a bidder:
19.1.1.1. Who is or the bidder’s director(s), trustee(s), shareholder(s),
member(s), partners(s) or any person(s) having controlling
interest in the bidder are restricted to conduct business with the
State.
19.1.1.2. Who is in the employ of the State or has a director(s), trustee(s),
shareholder(s), member(s), partners(s) or any person(s) having
controlling interest in the bidder who is in the employ of the State
as contemplated in the Public Administration Management Act,
and is prohibited from conducting business with the
State in terms of section of PAMA.
19.1.1.3. Who is in the service of the State or has a director(s), trustee(s),
shareholder(s), member(s), partners(s) or any person(s) having
controlling interest in the bidder and has not declared their
business interest as required in the applicable SBD4 form.
19.1.1.4. Has been found to have transgressed Prevention and Combating
of Corrupt Activities Act, (as amended).
19.1.1.5. Has been found to have transgressed or is transgressing the
Competition Act, (as amended).
19.1.2. ECIC shall not award a bid or contract or order to a bidder whose tax affairs
are not compliant, except to foreign bidders with no tax obligations in South
Africa.
19.1.3. For a bidder or the bidder’s director(s), trustee(s), shareholder(s),
member(s), partners(s) or any person(s) having controlling interest in the
bidder who have declared their business interest as required in the
applicable SBD4 form, ECIC will not award a bid to a bidder who has
declared their interest and:
19.1.3.1. Is prohibited from conducting business with the State; or
19.1.3.2. Does not have permission to conduct remunerative work outside
their employment.
19.1.4. ECIC will verify with the relevant Organ of State to determine if paragraphs
19.1.3.1 and 19.1.3.2 are not applicable.
19.1.5. ECIC will assume that, the person contemplated in paragraph 19.1.3 is
prohibited from conducting business with the State or the person does not
P a g e 22 | 42
Request for proposal: cybersecurity managed services and licenses
For a period of three years
have permission to conduct remunerative work outside their employment if
it does not receive any response within 21 days from such verification
request to an Organ of State.
19.1.6. ECIC will then recommend to award the bid to the bidder who achieved the
second highest preference points, and should it be established that the
bidder who achieved the second highest preference points has a person
contemplated in paragraph 19.1.3, ECIC will conduct verification as
contemplated in paragraphs 19.1.4and 19.1.5. This step can be performed
up to the bidder who achieved the third highest preference points.
19.2. Documents/information required as a condition of award
19.2.1. Proof of registration: Valid registration on the National Treasury Central
Supplier Database (CSD).
19.2.2. Completed and signed Standard Bidding Forms as follows:
Table 7
Invitation to bid (all bidders must ensure that this Form is duly
Sbd 1
completed and signed)
Declaration of Interest SBD 4
Preference Points Claim Form SBD 6.1
19.3. Sub-contracting
19.3.1. ECIC fully endorses the South African Government’s transformation and
empowerment objectives and in awarding the tender or contract,
preference may be given to bidders (Generics) who are willing to
subcontract not less than 30% of the contract to a company which is Black
Owned, Black Women Owned, Black Youth Owned, owned by Black
People with Disabilities, an EMEs and QSE. EME’s and QSE’s are allowed
to bid without subcontracting.
19.3.2. If contemplating subcontracting, please note that a bidder will not be
awarded points for Specific Goals if it is indicated in its Proposal that such
bidder intends subcontracting more than 30% (thirty percent) of the value
of the contract to an entity/entity that do not qualify for at least the same
points that the bidder qualifies for, unless the intended subcontractor is a
company which is Black Owned, Black Women Owned, Black Youth
Owned, owned by Black People with Disabilities, an EME and QSE , with
the capability to execute the subcontract.
19.3.3. A person awarded a contract may not subcontract more than 25% (twenty
five) of the value of the contract to any other enterprise that does not have
P a g e 23 | 42
Request for proposal: cybersecurity managed services and licenses
For a period of three years
an equal or higher Specific Goals than the person concerned, unless the
contract is subcontracted to an EME that has the capability and ability to
execute the subcontract.
19.4. ECIC’s rights
19.4.1. ECIC reserves the right to:
19.4.1.1. Amend any bid conditions, bid validity period, bid specifications,
or extend the bid closing date, all before the bid closing date.
Such amendments will be posted on the ECIC’s website under
the relevant tender information. All prospective bidders must
therefore ensure that they visit the website of ECIC
(www.ecic.co.za) regularly before they submit their bid response
to ensure that they are kept updated on any amendments in this
regard.
19.4.1.2. Cancel or withdraw this bid at any time, as a whole or in part
without reasons and without attracting any liability.
19.4.1.3. Award this bid to more than one bidder.
19.4.1.4. Award this bid in total or part.
19.4.1.5. Negotiate with all or some of the shortlisted bidders.
19.4.1.6. Not accept the lowest priced bid or award the bid to a bidder other
than the highest scoring bidder.
19.4.1.7. Conduct site visits at bidder’s offices and / or at client sites if so
required.
19.4.1.8. Request any relevant information and/ or documents to verify or
clarify information supplied in the bid response in relation, but not
limited to the structure of the bidding entity, bidder’s capacity,
proposed solution, proposed timelines etc.
19.5. Contract fees
19.5.1. Where a bidder indicates that its prices are subject to confirmation, or are
in any way conditional, such pricing will not be considered.
19.6. Confidentiality
19.6.1. Any information relating to the submissions, through the process or
otherwise, shall be treated in strict confidence. In submitting a response, a
Service provider agrees that it shall not be entitled to any information
disclosed by another respondent to ECIC, which ECIC has determined to
P a g e 24 | 42
Request for proposal: cybersecurity managed services and licenses
For a period of three years
be of a confidential nature. The content and details of the evaluation of
submissions will remain confidential to ECIC.
19.7. Other matters
19.7.1. If the ECIC does not accept any proposal, it will declare this bid process
closed and may then elect to:
19.7.1.1. Proceed on a completely different basis; and/or
19.7.1.2. Not to appoint any respondent (in the event it deems all or any of
the proposals not appropriate).
19.7.2. The ECIC reserves the right to engage in any processes required to
validate all claims made in the proposal.
19.7.3. The ECIC has the right to enter into negotiation with a prospective Service
provider regarding any terms and conditions, including fees, of a proposed
contract.
19.8. Disclaimer
19.8.1. The ECIC has produced this bid in good faith. However, the ECIC, its
agents and its employees and associates, do not warrant its accuracy or
completeness. The ECIC will not be liable for any claim whatsoever and
howsoever arising (including, without limitation, any claim in contract,
negligence or otherwise) for any incorrect or misleading information
contained in this bid due to any misinterpretation of this bid.
19.8.2. This bid is a request for proposals only and not an offer document; answers
to it must not be construed as acceptance of an offer or imply the existence
of a contract between the ECIC and the bidder.
19.9. Terms of engagement
19.9.1. The ECIC’s engagement of the service provider will be documented in a
contract between the ECIC and the appointed bidder.
P a g e 25 | 42
Request for proposal: cybersecurity managed services and licenses
For a period of three years
Annexes
Annexure A: Protection of personal information
Request for Quotations, it will provide personal information, which ECIC will process
for the sole purpose of evaluating the Bidder’s proposal. By submitting its proposal
in responding to this Request for Quotations, the Bidder hereby provide its consent
to the processing of its Personal Information by ECIC.
2.1. “Personal Information” shall bear the same meaning as ascribed to it under
Popi;
2.2. “POPI” means Protection of Personal Information Act, No. ;
2.3. “Responsible Party” shall bear the same meaning as ascribed to it under
POPI; and
2.4. “bid” means this Request for Quotations.
3.1. comply with the provisions of POPI as well as all applicable legislation as
amended or substituted from time to time;
3.2. treat all Personal Information strictly as defined within the parameters of
Popi;
3.3. process Personal Information only in accordance with the consent it was
obtained for, for the purpose agreed, as permitted by law;
3.4. secure the integrity and confidentiality of any Personal Information in its
possession or under its control by taking appropriate, reasonable technical
and organisational measures to prevent loss, damage, unauthorised
destruction, access, use, disclosure or any other unlawful processing of
Personal Information;
3.5. not transfer any Personal Information to any third party in a foreign country
unless such transfer complies with the relevant provisions of POPI regarding
transborder information flows; and
3.6. not retain any Personal Information for longer than is necessary for
achieving the purpose in terms of bid or in fulfilment of any other lawful
requirement.
4.1. identify reasonably foreseeable internal and external risks to the Personal
Information in its possession or under its control;
P a g e 26 | 42
Request for proposal: cybersecurity managed services and licenses
For a period of three years
4.2. establish and maintain appropriate security safeguards against the identified
risks;
4.3. regularly verify that the security safeguards are effectively implemented;
4.4. ensure that the security safeguards are continually updated in response to
new risks or deficiencies in previously implemented safeguards;
4.5. provide immediate notification to the Bidder if a breach in information
security or any other applicable security safeguard occurs; provide
immediate notification to the Bidder where there are reasonable grounds to
believe that the Personal Information has been accessed or acquired by any
unauthorised person;
4.6. remedy any breach of a security safeguard in the shortest reasonable time
and provide the Bidder with the details of the breach and, if applicable, the
reasonable measures implemented to address the security safeguard
breach;
4.7. provide immediate notification to the Bidder where the Bidder has, or
reasonably suspects that, Personal Information has been processed outside
of the purpose agreed to or consented to;
4.8. provide the Bidder, upon request, with all information of any nature
whatsoever relating to the processing of the Personal Information for the
purpose of the bid and any applicable law; and
4.9. notify the Bidder, if lawful, of receipt of any request for access to Personal
Information, in its possession and relating to the Bidder.
as well as the technical and organisational information security measures employed
by the ECIC to ensure compliance with the provisions of this Annexure.
P a g e 27 | 42
Request for proposal: cybersecurity managed services and licenses
For a period of three years
Annexure B: Format for fee proposal (Pricing Example)
This page has been left blank intentionally. Refer to the attached document titled Annexure
B (Format for fee proposal (Pricing Example)).
P a g e 28 | 42
Request for proposal: cybersecurity managed services and licenses for
A period of three years
Applicable standard bidding documents
Sbd 1
Part a
Invitation to bid
You are hereby invited to bid for the requirements of the export credit insurance corporation of south
Africa
Bid number: ECIC05P-2026/27 closing date: 6 october 2026 closing time: 11:00
Description cybersecurity managed services and licenses for a period of three years
Bid response documents must be sent to the following email address:
Preferably via email: [email protected]
Bidding procedure enquiries may be directed to technical enquiries may be directed to:
CONTACT PERSON Lulama Makwela CONTACT PERSON Lulama Makwela
E-MAIL ADDRESS [email protected] E-MAIL ADDRESS [email protected]
Supplier information
Name of bidder
Postal address
Street address
Telephone number code number
Cell phone number
Facsimile number code number
E-mail address
VAT registration number
Tax
Central supplier
Supplier compliance status compliance or maaa
DATABASE No:
System pin:
Are you the accredited are you a foreign
Yes No Yes No
Representative in south africa based supplier for
[If yes, answer the for the goods /services the goods /services
[If yes enclose proof] questionnaire below]
Offered? Offered?
Questionnaire to bidding foreign suppliers
Is the entity a resident of the republic of south africa (RSA)? yes NO
Does the entity have a branch in the RSA? yes NO
Does the entity have a permanent establishment in the RSA? yes NO
Does the entity have any source of income in the RSA? yes NO
Is the entity liable in the RSA for any form of taxation? Yes NO
If the answer is “NO” to all of the above, then IT is not a requirement to register for a tax compliance status
System pin code from the south african revenue service (SARS) and if not register as per 2.3 Below.
P a g e 29 | 42
Request for proposal: cybersecurity managed services and licenses for
A period of three years
Part b
Terms and conditions for bidding
1.1. Bids must be delivered by the stipulated time to the correct address. Late bids will
Not be accepted for consideration.
1.2. All bids must be submitted on the official forms provided– (not to be re-typed) or in
The manner prescribed in the bid document.
1.3. This bid is subject to the preferential procurement policy framework act, 2000 and
The preferential procurement regulations, the general conditions of contract
(Gcc) and, if applicable, any other special conditions of contract.
1.4. The successful bidder will be required to fill in and sign a written contract form (sbd7).
2.1 Bidders must ensure compliance with their tax obligations.
2.2 Bidders are required to submit their unique personal identification number (pin)
Issued by SARS to enable the organ of state to verify the taxpayer’s profile and tax
Status.
2.3 Application for tax compliance status (tcs) pin may be made via e-filing through the
SARS website: www.SARS.GOV.ZA.
2.4 Bidders may also submit a printed tcs certificate together with the bid.
2.5 In bids where consortia / joint ventures / sub-contractors are involved; each party
Must submit a separate tcs certificate / pin / csd number.
2.6 Where NO tcs pin is available but the bidder is registered on the central supplier
Database (csd), a csd number must be provided.
2.7 NO bids will be considered from persons in the service of the state, companies with
Directors who are persons in the service of the state, or close corporations with
Members persons in the service of the state.”
Nb: failure to provide / or comply with any of the above particulars may render the bid
Invalid.
Signature of bidder: ...................................................
Capacity under which this bid is signed: ...................................................
(Proof of authority must be submitted e.g., company resolution)
Date: ................................................
P a g e 30 | 42
Experience & Qualifications
Source: ECIC05P-2026_27.pdf9.1.3.1. The bidder must provide copies of Curriculum Vitae(s) and
certifications of at least one resource who will conduct the
assessments for ISO27001:2022 or latest and COBIT 2019 or latest.
The resource(s) must be certified as an ISO27001 lead auditor/
implementer and COBIT 2019 Design and Implementation with at least
3 years' experience.
9.1.4. Contactable references
9.1.4.1. The bidder must provide contactable reference letters for previous
0 1 2 3 4 5 0 1 2 3 Factor
(1 x
provided. and provided. references provided provided provided provided. vice-versa). provided. 1
or ISO27001). ISO27001).ALLOCATION x
or 1 references references reference reference references references references contactable COBIT2019 provided. provided. andPOINTS x five assessments
OF 2 COBIT2019 contactable contactable contactable contactable contactable contactable contactable references least references COBIT2019 No One Two Three Four At provided. No One (Either Two x Three (Either ISO27001DESCRIPTION DETAILS/INFORMATION 1.1.1. 1.1.2. 1.1.3. 1.1.4. 1.1.5. 1.1.6. 1.2.1. 1.2.2. 1.2.3. 1.2.4.
from Services Managed provided. delivery from letters details, the project was they delivery the Reference contactable contactable letters years where the project award. where years of Assessments: project 5 were project five Reference contact the than letterhead. letterhead. bid. provide where provide bid. DESCRIPTION Reference delivered, included. letters) than and/or year and/or assessments. older this be condition older this letters) Services of provided, organisation a COBIT2019 must Cybersecurity must be company is and (list/ be of company letters (list/ letters not date the was must be and similar not a CRITERIA a list on date on a of will bidder bidder be be must must closing Managed experience: The references Cybersecurity Reference date the must Where name project description delivered letters ISO27001 The references conducted Reference date closing must EVALUATION 1.2. 1.1.
letters
Contactable reference EVALUATION CRITERIA 1.
15 35 points
10 10 Sub- Points
3 5 3 5 3 rating
4 5 0 to to 0 to to 0 to Factor 1 4 1 4 1
(A x
2 all vice- lacks in- the with does noor the with at all clearly or and and and in-scope in-scope or provided references COBIT2019 vague, the vice-versa). all experience vague not required qualifications
x provided covers is the is or 3 of provided of provided. vague ofALLOCATION CV CV not requirements CV provided. is relevant qualifications qualifications assessments some COBIT2019 or is references covered copies of it x contactable not of the details the proposal with lack but or 2POINTS minimum requirements and CV assessments five copies minimum qualifications copies (AOF of provided ISO27001 of components. the clearly x proposal detailed however, contactable however, least 2 proposals not meet qualifications Four minimum ISO27001 At provided and versa). The components, The components details. The scope Either or Provided CV; minimum indicated. CV experience provided. CV not copies Provided CV;DESCRIPTION DETAILS/INFORMATION 1.2.5. 1.2.6. 2.1.1. 2.1.2. 2.1.3. 3.1.1. 3.1.2. 3.1.3. 3.2.1. 3.2.2.
at
senior in of with least must details, the project was proposal the services or be following project 5 including be history must Reference equivalent. at of CV lead/ the manager management Management where project award each or of contact of CV with The detailed the scope one a meet project applicable qualification. technical employment experience, suite. DESCRIPTION delivered, included. will the a The year least a (Project project be submit of at manager provided, organisation condition of other they a under and provide relevant security role. by conditions. Security/Cybersecurity CV is the was CV must be must CRITERIA list how a PMP Professional). Prince2. Any management Project years experience. a of will a must years' 365
7 bidder contract CV Where name project description delivered letters The outlining requirements and Provide equivalent accompanied certifications: Provide engineer/consultant/architect The Information least Microsoft EVALUATION 2.1. 3.1. 3.2.
5 3 5 rating
to 0 to to Factor 4 1 4
of or clearly required CVs minimum of of two with clearly indicating and not copies vague, not qualifications copies qualifications the is of experience clearly provided; meet no minimumALLOCATION CV
a
not or the details copies CVs CVs relevant and two required two provided. relevantPOINTS requirements and of do requirements of
OF of clearly however, minimum minimum minimum minimum indicated. CV experience provided. A provided requirements qualifications Provided qualifications CVs; minimum indicated. A the copies provided.DESCRIPTION DETAILS/INFORMATION 3.2.3. 3.3.1. 3.3.2. 3.3.3.
the must in of listed of two
Cove two Systems Systems Security security the authorised technical in suite, M365 or least include vulnerability an two experience experience at least certification. product resources of at by Hacker). equivalent, N-Able equivalent: may from least of 27001). information two
or DESCRIPTION or Information Information Information Certification. at as and years combined Ethical of security The 5 coupled copies international EDR with such (ISO/IEC by Security+. Security applicable least body. CVs (Certified Professional). certification transcript (Certified (Certified or CRITERIA at qualifications/certifications M365 certifications (Certified other of CISSP. CEH. ISO27001. CISA. CISM. CISSP Security CEH ISO27001 CISA Auditor). CISM Manager). CompTIA Microsoft Any qualification/ Provide resources the Kaspersky backups equivalent, management. have cybersecurity the below: accompanied following Proof certificate certification 3.3. EVALUATION
Evaluation criteria
15 100 points
0 1 to 5 Factor 2
the not the in the 10 the of
or is it than providing and and providing and years managed in or experience services. less experience in
to the of more provided years 7ALLOCATION
5 services, provided security provided services. provided or providing years than
10 in to determine experiencePOINTS profile than 7 profile profile more 5 less security security profile managed to profile.OF services. has of has has has
the company No bidder managed possible from Company bidder providing Company bidder years managed Company bidder experience securityDESCRIPTION DETAILS/INFORMATION 4.1.1. 4.1.2. 4.1.3. 4.1.4.
information international theinclude authorised profile has services services. company an company the security Certification. may from DESCRIPTION applicable cybersecurity Security+. Security qualification/ detailed least: managed specialisation. experience
at other transcript a of of certification body. CRITERIA or providing CompTIA Microsoft Any security certification. of Years in including Areas Provide indicating Proof certificate certification 4.1. EVALUATION
Bidders' experience EVALUATION CRITERIA 4. Total
Request for proposal: cybersecurity managed services and licenses
Pricing Schedule
Source: ECIC05P-2026_27.pdfSector Conduct Authority and Prudential Authority (FSP No: 30656). Currently exempted
in terms of FAIS Notice .
1.3. ECIC operates at the following address:
0157
2.1. The purpose of this Request for Proposal (RFP) is to appoint a service provider to
provide Managed Security Services, including conducting ISO27001:2022 and
COBIT2019 follow-up assessments, for a period of three (3) years.
3.1. The ECIC operates on a hybrid sourcing model for ICT comprising internal resources and
leveraging skills and competencies through outsourced services. The outsourced
services in the area of ICT Governance and Information Security are a critical strategic
position to ensure the ECIC have access to specialised skills as and when a need arises
for proactive and reactive support.
3.2. ECIC subscribes to the Corporate Governance of ICT Policy Framework, COBIT 2019
and ISO 27001 as guidelines for the implementation of ICT Governance and Information
Security Management within the Corporation, which is supported by the ISO27001:2022
and COBIT2019 assessments conducted every two years to determine the capability
maturity level of the Corporation.
3.3. The high-level summary of the current ECIC technology environment in line with the
required services:
3.3.1. KnowBe4.
Terms of Reference
Annexure B: Format for fee proposal (Pricing Example)
B (Format for fee proposal (Pricing Example)).
P a g e 28 | 42
Request for proposal: cybersecurity managed services and licenses for
Compliance Requirements
Source: ECIC05P-2026_27.pdf (RFP)Minimum functionality/qualifying score: 75
minimum score of 75
Tax compliance status
Tax compliance requirements
Tax compliance status (tcs) pin may be made via e-filing through the
Tcs pin is available but the bidder is registered on the central supplier
Csd number
Csd number must be provided
Central Supplier Database (CSD)
Central supplier database (csd), a csd number must be provided
and in the SBD 6.1 Form. Bidders are required to indicate how they claim points for
Points Allocation: 80 points
B-BBEE Details: ed for price of tender under consideration;
Pt = Comparative price of bid or offer under consideration; and
Pmin = Price of the lowest acceptable tender.
13.2. Depending on the bidder’s level of Specific Goals, a maximum of 20 Specific Goals
points may be awarded to a bidder. The points scored by a bidder for Specific Goals
will be added to the points allocated for price.
13.3. The table below reflects the number of points to be allocated to a bidder for Specific
Goals:
Table 3
Number of
points
The specific goals allocated points in terms of this tender
allocated
(80/20 system)
B-BBEE Procurement Recognition Level of 135% and at least
50.1% ownership by (or combination thereof):
a. Black people, or
b. Black female, or
c. Black Designated Group, or
d. Black Voting Rights.
B-BBEE Procurement Recognition Level of at least 110% and
at least 30% ownership by (or combination thereof):
a. Black people, or
b. Black female, or
c. Black Designated Group, or
d. Black Voting Rights.
B-BBEE Procurement Recognition Level of at least 110% and
up to 30% ownership by (or combination thereof):
a. Black people, or 5
b. Black female, or
c. Black Designated Group, or
d. Black Voting Rights.
Any other B-BBEE Procurement Recognition Level up to 110%. 0
[Bidders are required to indicate, in one block, the number of
Points they are claiming for specific goals in the table in
(Paragraph 4.1). In the event where a bidder makes a
P a g e 17 | 42
Request for proposal: cybersecurity managed services and licenses
For a period of three years
Terms of Reference
Mark (one mark), ecic will consider the corresponding points
To be the one which the bidder is claiming for. Where a bidder
Makes multiple marks or does not make any mark or indication
At all in
Section
Source: ECIC05P-2026_27.pdfPreference points will be awarded for specific goals in line with the 2022 Preferential Procurement Regulations. Bidders must claim specific goals in the SBD 6.1 form and provide substantiating documents. Bids that do not provide the required documents and do not indicate specific goals claimed will not be awarded. Preference may be given to bidders willing to subcontract at least 30% of the contract value to qualifying entities, unless the subcontractor is Black Owned, Black Women Owned, Black Youth Owned, or owned by Black people with disabilities. A person awarded a contract may not subcontract more than 25% of the contract value to an enterprise that does not qualify for the same points.
Sets the constitutional standard for fair, equitable, transparent, competitive and cost-effective public procurement.
Relevant because this is a South African public-sector procurement opportunity.
Act 5 of 2000
Covers preferential procurement and preference-point systems used in public tenders.
Relevant because this is a South African public-sector procurement opportunity.
Act 12 of 2004
Supports anti-corruption controls and supplier integrity in procurement processes.
Relevant because this is a South African public-sector procurement opportunity.
Act 28 of 2024
Provides the national framework for public procurement across government.
Relevant because this is a South African public-sector procurement opportunity.
Act 2 of 2000
Supports access to tender records, award decisions and public-sector procurement information.
Relevant because this is a South African public-sector procurement opportunity.
Act 3 of 2000
Supports lawful, reasonable and procedurally fair administrative tender decisions.
Relevant because this is a South African public-sector procurement opportunity.
Address
Extension 73, 11 Bylsbridge Blvd, Highveld, Centurion, 0157, South Africa
Source confidence
High source confidence
Official source
eTenders.gov.za
Documents found
1
Last checked
22 Sept 2026
AI status
Enhanced
Data conflicts
None detected
This tender has strong source evidence, including source metadata and supporting tender information synced from the government tender portal.
Tenders SA is not the issuing authority. All tenders are automatically synced from the official government tender portal. Always confirm final submission details, closing dates, briefing sessions, eligibility requirements, and documents on the official government portal before applying.
Contact
+27 12 471 3800[email protected]ecic.co.zaExtension 73, 11 Bylsbridge Blvd, Highveld, Centurion, 0157, South Africa
Provinces Active
Industries
Get deep intelligence on Information and communication. Unlock full pricing strategies, bid frequency, and historical win rates.
Learn how to submit a winning bid with these related articles
Win government telecom contracts including fiber rollout, network infrastructure, mobile services, and broadband projects. ICASA licensing and compliance.
South Africa is bridging the digital divide. Explore the provincial and municipal broadband rollout projects and the technical requirements for bidding.
Avoid disqualification with our technical compliance checklist for IT bids. From OEM authorizations to POPIA and ISO standards.
Master the process of winning government IT tenders in South Africa. Learn about SITA registration, compliance requirements, and strategies for success.
💡 Want more tendering tips and strategies?
Explore Our Blog