Broad-Based Black Economic Empowerment Act (B-BBEE Act)
Act 53 of 2003
Provides the empowerment-compliance context often used in public-sector supplier evaluation.
Relevant because this is a South African public-sector procurement opportunity.
Documents available on tender detail page
Tender Type
Request for Quotation
Delivery Location
Block D, Hatfield Gardens 333 Grosvenor Street - Hatfield - PRETORIA - 0083
Organization Type
GOVERNMENT
Published
01 Oct 2026
OCDS Reference
ocds-9t57fa-172467
The national lotteries commission requires one licensed cloud-based vulnerability management system, supplied, delivered, installed and configured, licensed for 12 months, covering 500 user devices and servers (windows and linux) as well as network devices and the NLC website. The system must scan in real time, provide dashboard monitoring, produce risk and severity reporting, flag end of life and end of support assets, and patch detected vulnerabilities where applicable. The work is a once-off service that starts on appointment and receipt of an official NLC purchase order. The single most consequential consideration is that a valid oem certificate or equivalent written oem authorisation is a mandatory pre-qualification requirement, and any missing or unsigned mandatory document disqualifies the bid before evaluation.
Closing and submission: quotations close on 06 October 2026 at 11:00 (South African Standard Time) and must be submitted online through the e-tender portal only — no email submissions; late or incomplete submissions are rejected, and bidders should submit at least 30 minutes early as transmission delays, network problems, load shedding and portal difficulties are the bidder's risk.
Mandatory OEM authorisation: a valid certificate from the Original Equipment Manufacturer or equivalent written OEM authorisation is a pre-qualification requirement; bids without it are disqualified and not evaluated further.
CSD and tax compliance: bidders must self-register on National Treasury's Central Supplier Database, provide their CSD registration number and a CSD summary report, and hold a valid tax compliance status on the closing date; submit a SARS tax compliance status PIN or printed TCS certificate, with each consortium, joint venture or sub-contracting party submitting its own PIN/TCS and CSD number.
B-BBEE evidence: a valid B-BBEE certificate or sworn affidavit is required to claim preference points, and a joint venture must submit a joint/consolidated B-BBEE certificate or affidavit; without the required proof the specific-goals points are treated as not claimed.
Evaluation and specific goals: the 80/20 preference point system applies under the PPPFA and Preferential Procurement Regulations 2022 — 80 points for price and 20 for specific goals, allocated as black ownership 8/4/0 points (100% / 51–99% / under 51%), black women ownership 4/2/0 (100% / 30–99% / under 30%), black youth ownership 4/2/0 (100% / 30–99% / under 30%) and owners with disability 4/2/0 (20% or more / over 10% but under 20% / under 10%); no minimum functionality or qualifying score is stated.
Technical scope and bidder information: supply one licensed instance covering 500 user devices and servers, with real-time scanning of user laptops, Windows and Linux servers, network devices (switches, routers, firewall) and www.nlcsa.org.za, real-time dashboard monitoring, risk assessment reporting on a 0–1000 or percentage score matrix, End of Support/End of Life and exploitable-vulnerability reporting, Low/Medium/High/Critical severity reporting and patching where applicable; bidders must also state delivery lead time from receipt of an NLC purchase order, the delivery method, and what installation and configuration require and how long it will take.
Pricing format: complete the price schedule with a single all-inclusive total in Rand for the one line item, and submit financial/pricing information as a separate attachment from the technical response; no bid security, performance guarantee or retention is specified.
Enquiries and disqualification risks: send RFQ queries to [email protected] no later than 24 hours before the closing date (bidding procedure enquiries: 012 432 1309 or [email protected]; technical enquiries: 012 432 1308); no compulsory briefing or site visit is stated, and collusion, canvassing NLC officers between closing and award, listing on the Register for Tender Defaulters or List of Restricted Suppliers, or being a person in the service of the state will disqualify a bidder.
Continue with tenders sharing this issuer, category, or province.
Return to this tender’s issuing organisation, province, or category.
Continue with tenders sharing this issuer, category, or province.
Date & Time
Tuesday, 06 October 2026 - 11:00
Venue
null
Categories
Request for Quotation
Block D, Hatfield Gardens 333 Grosvenor Street - Hatfield - PRETORIA - 0083
Tenders in this industry often require registration with these bodies.
Recommended Certifications
Having these can improve your winning chances: IITPSA Membership, ISO 27001 (Information Security Management), ISO 20000 (IT Service Management), CISSP
AI Document Analysis Stages
Description
Source: RF2026-010-001 Vulnerability Management System.pdf01 Oct
2026
Tender Published
Tender was published
06 Oct
2026
Closing Date
Tender closing date
These references help suppliers understand the public-procurement framework around this opportunity. They are generated from the tender category, issuing organisation type and procurement context.
These rules commonly apply to South African public-sector procurement.
Act 53 of 2003
Provides the empowerment-compliance context often used in public-sector supplier evaluation.
Relevant because this is a South African public-sector procurement opportunity.
Act 108 of 1996 (s217)
This is general procurement context, not legal advice. Always verify requirements in the official tender documents and issuing authority notices.
RF2026-010-001 Vulnerability Management System.pdf
Supply, delivery, installation and configuration of a cloud-based vulnerability management system for the National Lotteries Commission, licensed for 12 months and covering 500 user devices and servers (Windows and Linux), plus network devices and the NLC website.
To download these documents and access AI-powered analysis, visit the main tender page.
Matched by category & region
Free guidance to prepare before you bid
Not sure if your business is ready for this tender? Check CSD, CIDB, and B-BBEE requirements, run a readiness assessment, and move from opportunity to submission.
Open Supplier Readiness HubMedian Estimate
R 2 352 363
Range
Based on 25 comparable awarded tenders. Companies with similar profiles typically bid near the median.
* Estimates are based on historical data and do not guarantee actual award values.
We refine every tender document through these stages so you can brief your team and prepare your bid with confidence. Anything marked as "in progress" will be upgraded automatically — no action required from you.
The National Lotteries Commission requires a service provider to supply, deliver, install and configure a cloud-based vulnerability management system licensed for 12 months, covering 500 user devices and servers running Windows and Linux.
Important Dates
Source: RF2026-010-001 Vulnerability Management System.pdf (RFQ)Closing
Advertisement
Bid validity
Clarification questions
No compulsory briefing or site visit is stated.
Contact Information
Source: RF2026-010-001 Vulnerability Management System.pdf (RFQ)Bidding procedure enquiries
Technical enquiries
RFQ queries
Submission
Postal address
National Lotteries Commission (NLC)
P.O Box 1556
Brooklyn Square 0083
Pretoria
Submission Guidelines
Source: RF2026-010-001 Vulnerability Management System.pdf (RFQ)Submission method
Format
Returnable documents
Disqualification risks
Returnable Documents
Source: RF2026-010-001 Vulnerability Management System.pdf (RFQ)Returnable documents: completed and signed SBD 1, SBD 4 and SBD 6.1; signed POPIA consent form; CSD report showing a valid tax compliant status; valid B-BBEE certificate or sworn affidavit; valid OEM certificate or equivalent written OEM authorisation; and the completed pricing schedule/quotation.
Evaluation Criteria
Source: RF2026-010-001 Vulnerability Management System.pdf (RFQ)System
Stage 1 — Closing and opening
Stage 2 — Administrative compliance and mandatory requirements
Stage 3 — Price and specific goals (80/20)
Stage 4 — Due diligence
Stage 5 — Contract and award
Technical Specifications
Source: RF2026-010-001 Vulnerability Management System.pdf (RFQ)Scope
Scanning
Monitoring and reporting
Remediation
Information to be provided by the bidder
Duration
Experience & Qualifications
Source: RF2026-010-001 Vulnerability Management System.pdfNo minimum years of experience or key personnel qualifications are stated. The National Industrial Participation Programme applies to contracts with imported content and is obligatory; bidders must sign and submit the relevant Standard Bidding Document. Quotations must be submitted in English.
Quality Management
Source: RF2026-010-001 Vulnerability Management System.pdfNLC conducts regular supplier performance reviews against the contract deliverables using supplier evaluation forms, with at least an annual review for contracts longer than a year and a review at completion for shorter contracts. Ad-hoc reviews are held where non-performance is identified outside the review period. Non-performance is addressed by a formal letter setting out the underperforming areas and the remedial action required within specified time frames; failure to comply leads to escalating performance management action. Either party may request a joint performance review.
Pricing Schedule
Source: RF2026-010-001 Vulnerability Management System.pdfThe price schedule covers the supply, delivery, installation and configuration of a cloud-based vulnerability management system: one licensed instance capable of scanning user laptops, servers (Windows and Linux), network devices and the website, with real-time dashboard monitoring, reporting, coverage of 500 devices and patching capability. Quantity is 1 and the bidder must state a single total price, all inclusive.
Financial Requirements
Source: RF2026-010-001 Vulnerability Management System.pdf (RFQ)Pricing format
Contract price adjustment
No bid security, performance guarantee, retention or stated payment terms are specified.
Compliance Requirements
Source: RF2026-010-001 Vulnerability Management System.pdf (RFQ)Central Supplier Database
Tax
B-bbee
Product authorisation
Standard forms
Other
Contractual Terms
Source: RF2026-010-001 Vulnerability Management System.pdfThe bidder warrants that all employees, including those of any sub-contractor, are covered under the Compensation for Occupational Injuries and Diseases Act, and that cover remains in force for the duration of the adjudication and any subsequent agreement. The Commission may request proof of registration and good standing with the Compensation Fund. Personal information is processed in line with POPIA and the Commission's data privacy policy, and bids are treated as contractually binding. The bidder must notify the Commission in writing of any unauthorised access to personal information, including through cybercrime, and report it to the relevant authorities.
Special Conditions
Source: RF2026-010-001 Vulnerability Management System.pdf (RFQ)The service is a once-off engagement effective from the date of appointment and issue of an official NLC purchase order. No goods may be delivered or services rendered before an official purchase order is received. Bidders and their agents may not issue news releases about the RFQ or any resulting agreement without the Commission's consent. The RFQ document is confidential and its intellectual property vests with the Commission. Late and incomplete submissions are not accepted.
Requirements
Source: RF2026-010-001 Vulnerability Management System.pdf (RFQ)Mandatory documents: completed and signed SBD 1, SBD 4 and SBD 6.1; signed POPIA consent form; CSD registration with a valid tax compliant status; valid B-BBEE certificate or sworn affidavit; valid OEM certificate or equivalent written OEM authorisation. Bids that do not fully meet the mandatory requirements are disqualified.
Section
Source: RF2026-010-001 Vulnerability Management System.pdfEvaluation uses the 80/20 preference point system. Stage 1: closing and opening on 06 October 2026 at 11:00, with late bids rejected. Stage 2: administrative compliance and mandatory requirements, with non-compliant bids disqualified. Stage 3: 80 points for price and 20 points for specific goals — black ownership up to 8 points, black women ownership up to 4 points, black youth ownership up to 4 points, and ownership by persons with disability up to 4 points. Stage 4: due diligence, including verification, office inspection, reference checks and financial stability assessment. Stage 5: contract and award, with possible negotiation and a request for best and final offers.
Sets the constitutional standard for fair, equitable, transparent, competitive and cost-effective public procurement.
Relevant because this is a South African public-sector procurement opportunity.
Act 5 of 2000
Covers preferential procurement and preference-point systems used in public tenders.
Relevant because this is a South African public-sector procurement opportunity.
Act 12 of 2004
Supports anti-corruption controls and supplier integrity in procurement processes.
Relevant because this is a South African public-sector procurement opportunity.
Act 28 of 2024
Provides the national framework for public procurement across government.
Relevant because this is a South African public-sector procurement opportunity.
Act 2 of 2000
Supports access to tender records, award decisions and public-sector procurement information.
Relevant because this is a South African public-sector procurement opportunity.
Act 3 of 2000
Supports lawful, reasonable and procedurally fair administrative tender decisions.
Relevant because this is a South African public-sector procurement opportunity.
These rules are linked to the work category, industry, or regulated service area.
Act 4 of 2013
Relevant where personal information, data systems, biometrics, records or citizen information may be processed.
Relevant because this tender appears to involve ICT systems, software, digital services, or public-sector technology procurement.
Act 88 of 1998
Relevant to public-sector ICT procurement and government technology acquisition routes.
Relevant because this tender appears to involve ICT systems, software, digital services, or public-sector technology procurement.
Act 25 of 2002
Relevant to electronic transactions, digital procurement channels, e-signatures and online service delivery.
Relevant because this tender appears to involve ICT systems, software, digital services, or public-sector technology procurement.
Address
Block D, 333 Grosvenor St, Hatfield, Pretoria, 0083, South Africa
Source confidence
High source confidence
Official source
eTenders.gov.za
Documents found
1
Last checked
02 Oct 2026
AI status
Enhanced
Data conflicts
None detected
This tender has strong source evidence, including source metadata and supporting tender information synced from the government tender portal.
Tenders SA is not the issuing authority. All tenders are automatically synced from the official government tender portal. Always confirm final submission details, closing dates, briefing sessions, eligibility requirements, and documents on the official government portal before applying.
Contact
012-432-1470[email protected]www.nlcsa.org.zaBlock D, 333 Grosvenor St, Hatfield, Pretoria, 0083, South Africa
Key Personnel
Provinces Active
Industries
Learn how to submit a winning bid with these related articles
South Africa's metros are evolving. Learn how to position your ICT firm for high-value smart city infrastructure and digital transformation contracts.
A guide for IT companies to navigate the dual procurement paths of the State Information Technology Agency (SITA) and the Gauteng Department of Education (GDE).
Avoid disqualification with our technical compliance checklist for IT bids. From OEM authorizations to POPIA and ISO standards.
Win government telecom contracts including fiber rollout, network infrastructure, mobile services, and broadband projects. ICASA licensing and compliance.
💡 Want more tendering tips and strategies?
Explore Our BlogGet deep intelligence on Information and communication. Unlock full pricing strategies, bid frequency, and historical win rates.