Broad-Based Black Economic Empowerment Act (B-BBEE Act)
Act 53 of 2003
Provides the empowerment-compliance context often used in public-sector supplier evaluation.
Relevant because this is a South African public-sector procurement opportunity.
Documents available on tender detail page
Tender Type
Request for Bid(Open-Tender)
Delivery Location
11 Byls Bridge Boulevard - Doringkloof - Centurion - 0157
Organization Type
GOVERNMENT
Published
03 Jun 2026
OCDS Reference
ocds-9t57fa-158033
The south african civil aviation authority (SACAA) seeks a supplier to provide 24/7/365 cyber risk operations center (croc) services, including managed detection and response (mdr), platform administration, and security awareness training, leveraging sacaa’s existing trend micro ecosystem for a period of three years.
Description
Source: Tender Document - Cyber Security Monitoring Services - June 2026.pdfSACAA requires a 3-year contract for 24/7/365 Cyber Security Monitoring and Managed Detection and Response (MDR) services. The solution must leverage SACAA’s existing Trend Micro cybersecurity ecosystem (Trend Vision One platform), which includes endpoint, server, network, email, identity, cloud, and SIEM capabilities. The goal is to establish a Cyber Risk Operations Center (CROC) model, replacing a traditional SOC, with: MDR for 24×7 monitoring, alert correlation, investigation, threat hunting, and guided response; Platform Administration by South African-based personnel for sensor health, configuration governance, policy optimisation, SOAR playbook development, and reporting. The approach maximises SACAA’s technology investment while enhancing national cyber resilience and operational visibility.
Bidders are required to submit their bids on time to avoid being late. Our new office park has strigent security measures therefore each bidder will be required to make a prior access code arrangement with betty monyeki on 082 885 4270 or cynthia motaung on 083 461 6534.
Categories
Request for Bid(Open-Tender)
11 Byls Bridge Boulevard - Doringkloof - Centurion - 0157
These references help suppliers understand the public-procurement framework around this opportunity. They are generated from the tender category, issuing organisation type and procurement context.
Tender Document - Cyber Security Monitoring Services - June 2026.pdf
The South African Civil Aviation Authority (SACAA) invites bids for the provision of Cyber Security Monitoring and Managed Detection and Response (MDR) services for a period of three years. The services must integrate with SACAA's existing Trend Micro ecosystem, including Trend Vision One, to establish a Cyber Risk Operations Center (CROC). The scope includes 24/7 monitoring, threat detection, incident response, platform administration, managed risk (CREM), and security awareness training. The tender closes on 24 June 2026 at 11:00 UTC, with a bid validity period of 180 days.
Date & Time
Wednesday, 24 June 2026 - 11:00
Venue
null
03 Jun
2026
Tender Published
Tender was published
24 Jun
2026
Closing Date
Tender closing date
Median Estimate
R 760 326
Range
Based on 25 comparable awarded tenders. Companies with similar profiles typically bid near the median.
* Estimates are based on historical data and do not guarantee actual award values.
Learn how to submit a winning bid with these related articles
Win consulting, legal, accounting, and engineering service contracts with government. Learn registration requirements and proposal strategies.
Comprehensive guide to Institute of IT Professionals South Africa membership. Certification levels, requirements for ICT professionals, and how IITPSA membership enhances credibility for SITA and government IT tenders.
A strategic guide to getting listed on government consultancy, legal, and engineering panels. Learn why panels are the gateway to steady public sector work.
Master the art of the consulting bid. How to structure your methodology, price your services competitively, and score maximum evaluation points.
💡 Want more tendering tips and strategies?
Explore Our BlogImportant Dates
Source: Tender Document - Cyber Security Monitoring Services - June 2026.pdf (TENDER)Closing date: 24 June 2026 at 11:00. Clarification queries deadline: 17 June 2026 (submit to [email protected]). Bid validity period: 180 days from closing date. No briefing session.
Contact Information
Source: Tender Document - Cyber Security Monitoring Services - June 2026.pdf (TENDER)All enquiries must be submitted in writing to: [email protected]. For office park access codes: Betty Monyeki (082 885 4270) or Cynthia Motaung (083 461 6534). Bidding procedure/technical enquiries: Ntombizodwa Duma (011 545 1262, [email protected]). Submission address: BID BOX MARKED 2, SACAA Bid Committee, South African Civil Aviation Authority, Byls Bridge Office Park, Olievenhoutbosch Road & Jean Ave, Centurion, 0157.
Submission Guidelines
Source: Tender Document - Cyber Security Monitoring Services - June 2026.pdf (TENDER)Submit bids in a three-envelope system: Envelope 1 (mandatory documents), Envelope 2 (technical proposal - 1 original + 1 copy), Envelope 3 (pricing schedule - 1 original + 1 copy). Deposit all envelopes in the BID BOX MARKED 2 at SACAA Head Office, Byls Bridge Office Park, Olievenhoutbosch Road & Jean Ave, Centurion, 0157 by 11:00 on 24 June 2026. Late bids or submissions to incorrect boxes will be disqualified. No electronic submissions (email, fax, etc.) accepted. Amendments must be submitted with the original bid in a separate envelope marked 'Amendment to bid' before the deadline. Prior access code arrangement is required for office park entry: contact Betty Monyeki (082 885 4270) or Cynthia Motaung (083 461 6534). Bids must be neatly bound; no USBs/memory sticks accepted. All documents must be in English. Bid validity period: 180 days from closing date.
Evaluation Criteria
Source: Tender Document - Cyber Security Monitoring Services - June 2026.pdf (TENDER)Evaluation follows a 3-phase process: Phase 1 (Mandatory SCM Compliance): Verify completeness of SBD1, SBD3, SBD4, SBD6.1, CSD registration, tax compliance (TCS PIN or CSD number), B-BBEE certificate/affidavit, and no state-employed directors. Non-compliance disqualifies the bid. Phase 2 (Functionality - 100 points, min 70 required to advance): Company References (20-40 points: 3+ contactable CROC/MDR references from last 4 years), Methodology (10-20 points: incident response, threat hunting, escalation, industry standards alignment), Ability to Support Proposed Infrastructure (40 points: 1x CISM, 1x CEH, 4x ISC2 Cybersecurity, 4x Trend Micro Platform Advanced certifications; min 10 employees, no dual roles). Phase 3 (80/20 Preference Points): 80 points for price (lowest bid = 80, others scaled via formula Ps = 80(1 - (Pt-Pmin)/Pmin)), 20 points for B-BBEE (Level 1=20, Level 2=18, Level 3=14, Level 4=12, Level 5=8, Level 6=6, Level 7=4, Level 8=2, Non-Compliant=0). SACAA reserves the right to award to empowerment companies or joint ventures with empowerment partners.
Technical Specifications
Source: Tender Document - Cyber Security Monitoring Services - June 2026.pdf (TENDER)Provide 24/7/365 Cyber Risk Operations Center (CROC) services using SACAA’s existing Trend Micro ecosystem (Trend Vision One platform). Services include: Managed Detection and Response (MDR): 24/7 monitoring across endpoint, server, email, network, identity, cloud; AI/ML-based correlation; IoC/IoA sweeping; MITRE ATT&CK aligned detection; full investigations (attack vector, lateral movement, dwell time); response actions (endpoint isolation, process termination, memory dumps, remote shell, email quarantine, URL/IP/file hash blocking); threat hunting (indicator-based, behavioural, MITRE TTP, anomaly detection); severity escalation (Urgent: 24h updates, Critical: 1h notification, Major: correlation required, Minor: logged). Platform Administration: Daily health checks; policy creation/tuning; troubleshooting ingestion gaps; weekly/monthly/on-demand reporting; up to 10 SOAR playbooks annually; quarterly posture reviews. All platform admin personnel must be South Africa-based. Managed Risk (CREM): Enterprise-wide risk scoring; high-risk device/user/workload identification; weekly remediation guidance; posture tracking; executive reporting. Security Awareness Training: Monthly phishing simulations; quarterly training modules; behaviour-based user risk scoring; completion/risk improvement reporting. Incident Response: Logging, categorisation, prioritisation (per SACAA Priority Matrix), evidence collection, attack chain reconstruction, containment recommendations, post-incident reviews. Monitored Environment: Ingest and correlate telemetry from SACAA’s Azure, cloud, and on-prem systems (e.g., API Connections, App Services, Cosmos DB, Key Vaults, Virtual Machines, Networks) into Trend Vision One (SIEM, analytics, SOAR). Additional Credit Requirements: Provide extra ingestion and retention credits for 6-month data retention. Third-party SIEMs may only complement, not replace, Trend Vision One.
Methodology
Source: Tender Document - Cyber Security Monitoring Services - June 2026.pdfBidders must submit a comprehensive, fully documented methodology outlining their approach to: Incident Response (alignment with industry standards, capability), Threat Hunting, Escalation Methodology. This section is worth 10-20 points in the functionality evaluation.
Pricing Schedule
Source: Tender Document - Cyber Security Monitoring Services - June 2026.pdfSubmit pricing in ZAR only, using the official SBD3 form (not re-typed). Include: Ceiling price (total estimated cost for all phases, inclusive of VAT); hourly and daily rates for all personnel; cost per phase with man-days; travel expenses (actual costs only, proof required; >40km round trips reimbursed for non-monitoring staff); other expenses (e.g., accommodation, reproduction) with proof. Specify if rates are firm for the contract period or subject to adjustment (e.g., CPI). Deviation from the prescribed format may disqualify the bid. Offer must remain valid for 180 days from closing date.
Financial Requirements
Source: Tender Document - Cyber Security Monitoring Services - June 2026.pdf (TENDER)Pricing must be in South African Rands (ZAR), firm for the contract period (3 years), and inclusive of VAT. Submit a detailed price schedule (SBD3) with: Ceiling price for total estimated time/completion of all phases; hourly/daily rates for all personnel involved; cost per phase and man-days; travel expenses (actual costs only, proof required; >40km round trips reimbursed for non-monitoring staff); other expenses (e.g., accommodation, reproduction) with proof. Deviation from the prescribed pricing schedule format may disqualify the bid. Payment terms: Certified invoices required for all expenses. Contract validity: 180 days from closing date. SACAA reserves the right to reject non-responsive or incomplete price lists.
Compliance Requirements
Source: Tender Document - Cyber Security Monitoring Services - June 2026.pdf (TENDER)Mandatory: Registration on Central Supplier Database (CSD) with valid supplier number. Tax Compliance: Submit TCS PIN (from SARS) or CSD number. For consortia/joint ventures/sub-contractors, each party must submit separate TCS/CSD proof. Foreign bidders: Confirm RSA tax liability if applicable; if no RSA presence, TCS PIN not required. B-BBEE: Submit verification certificate or sworn affidavit (EMEs/QSEs). Non-compliance = 0 points for Specific Goals. Disqualification: Bidders with directors/members/partners employed by the state; listed in Tender Defaulters Register or Restricted Suppliers List; collusion or corrupt practices (SBD4 declaration required). Mandatory Documents: SBD1 (Invitation to Bid - completed/signed), SBD3 (Pricing Schedule - completed), SBD4 (Bidder’s Disclosure - completed/signed), SBD6.1 (Preferential Procurement Points - completed/signed). Failure to submit any mandatory document renders the bid non-responsive.
Environmental
Source: Tender Document - Cyber Security Monitoring Services - June 2026.pdfEnvironmental requirements are limited to cybersecurity threat detection: Provider must deliver indicator-based threat hunting, behavioural and Indicator of Attack (IOA) hunting, MITRE TTP (Tactics, Techniques, Procedures) hunting, and anomaly/environmental drift detection as part of the MDR service.
Contractual Terms
Source: Tender Document - Cyber Security Monitoring Services - June 2026.pdfContract duration: 3 years. Dispute resolution: Negotiation (10 days) → Mediation (15 days, via Arbitration Foundation of Southern Africa) → Arbitration (15 days, expedited, via AFSA). Arbitration held in Centurion, South Africa, in English, under South African law. Arbitrator’s award is final and binding; can be made an order of court. Parties may seek interim court relief (interdict/mandamus) for urgent matters. SACAA reserves rights to: amend bid conditions/validity/specifications or extend closing date; reject lowest bid; award to empowerment companies or joint ventures; award in part/whole or withdraw without reasons; conduct site visits. Bid validity: 180 days from closing date. Withdrawal or failure to fulfill contract may result in liability for additional costs or set-off against monies due. SACAA’s interpretation of bid documents is final in case of discrepancies.
Section
Source: Tender Document - Cyber Security Monitoring Services - June 2026.pdfBidders are evaluated under the Preferential Procurement Policy Framework Act, 2000 and Regulations, 2022. Phase 1: Mandatory SCM compliance (CSD registration, tax compliance, B-BBEE proof, SBD forms). Phase 2: Functionality (100 points, min 70 to advance): Company References (20-40 points for 3-5+ CROC/MDR references from last 4 years), Methodology (10-20 points for incident response, threat hunting, escalation, industry standards), Ability to Support Infrastructure (40 points for certifications: 1x CISM, 1x CEH, 4x ISC2 Cybersecurity, 4x Trend Micro Platform Advanced; min 10 employees). Phase 3: 80/20 Preference Points: 80 for price (Ps = 80(1 - (Pt-Pmin)/Pmin)), 20 for B-BBEE (Level 1=20 to Non-Compliant=0). SACAA may award to empowerment companies or joint ventures with empowerment partners.
Tenders in this industry often require registration with these bodies.
Recommended Certifications
Having these can improve your winning chances: CA(SA) - Chartered Accountant, PMI-PMP (Project Management Professional), Prince2 Practitioner, Six Sigma Certification
These rules commonly apply to South African public-sector procurement.
Act 53 of 2003
Provides the empowerment-compliance context often used in public-sector supplier evaluation.
Relevant because this is a South African public-sector procurement opportunity.
Act 108 of 1996 (s217)
Sets the constitutional standard for fair, equitable, transparent, competitive and cost-effective public procurement.
Relevant because this is a South African public-sector procurement opportunity.
Act 5 of 2000
Covers preferential procurement and preference-point systems used in public tenders.
Relevant because this is a South African public-sector procurement opportunity.
Act 12 of 2004
Supports anti-corruption controls and supplier integrity in procurement processes.
Relevant because this is a South African public-sector procurement opportunity.
Act 28 of 2024
Provides the national framework for public procurement across government.
Relevant because this is a South African public-sector procurement opportunity.
Act 2 of 2000
Supports access to tender records, award decisions and public-sector procurement information.
Relevant because this is a South African public-sector procurement opportunity.
Act 3 of 2000
Supports lawful, reasonable and procedurally fair administrative tender decisions.
Relevant because this is a South African public-sector procurement opportunity.
This is general procurement context, not legal advice. Always verify requirements in the official tender documents and issuing authority notices.
To download these documents and access AI-powered analysis, visit the main tender page.
Organization
South African Civil Aviation AuthorityContact Person
Ntombizodwa Duma
Phone
011-545-1262
[email protected]
Website
www.caa.co.za/
Address
Byls Bridge Office Park, 11 Bylsbridge Blvd, Doringkloof, Centurion, 0157, South Africa
Source confidence
High source confidence
Official source
eTenders.gov.za
Documents found
1
Last checked
03 Jun 2026
AI status
Enhanced
This tender has strong source evidence, including source metadata and supporting tender information synced from the government tender portal.
Tenders SA is not the issuing authority. All tenders are automatically synced from the official government tender portal. Always confirm final submission details, closing dates, briefing sessions, eligibility requirements, and documents on the official government portal before applying.
Key Personnel
Data conflicts
None detected
Byls Bridge Office Park, 11 Bylsbridge Blvd, Doringkloof, Centurion, 0157, South Africa
Get deep intelligence on Services: Professional. Unlock full pricing strategies, bid frequency, and historical win rates.