Broad-Based Black Economic Empowerment Act (B-BBEE Act)
Act 53 of 2003
Provides the empowerment-compliance context often used in public-sector supplier evaluation.
Relevant because this is a South African public-sector procurement opportunity.
Issuing Organization
National Home Builders Registration CouncilLocation
Gauteng
Closing Date
10 Sept 2026
Documents available on tender detail page
Tender Type
Request for Bid(Open-Tender)
Delivery Location
27 Leeuwkop - Sandton - Sunninghill - 2191
Organization Type
GOVERNMENT
Published
19 Aug 2026
OCDS Reference
ocds-9t57fa-166150
The national home builders registration council (nhbrc) seeks a managed cybersecurity services provider for a five-year term to deliver end-to-end security operations across its national office network. The single most consequential requirement is that the bidder must operate a fully functional 24/7/365 security operations centre located within south africa, with all analyst access to nhbrc data performed from within the country, and must hold valid iso/iec 27001:2022 and iso 9001 certifications applicable to the managed security services environment.
Closing date and time: 10 September 2026 at 11:00; submission only via the National Treasury eTender Portal (https://www.etenders.gov.za/).
Non-compulsory virtual briefing session: 28 August 2026 at 11:00 via Microsoft Teams (link in RFP); email [email protected] before 11:00 if connection issues arise.
Mandatory disqualifying documents: signed SBD 1, SBD 3.1 (Pricing Schedule with detailed cost breakdown and annual escalation), SBD 4, SBD 6.1, CSD report/MAAA number, latest CIPC documents, valid SARS PIN, signed teaming agreement, certified director IDs, valid ISO/IEC 27001:2022 certificate, valid ISO 9001 certificate, and certified copy of Cyber Security Professional Indemnity and/or Cyber Liability Insurance with minimum R10,000,000 coverage.
Bidder must have minimum five years' proven experience delivering enterprise-grade managed cybersecurity services and at least three contactable reference letters for similar engagements.
Bidder must hold valid ISO/IEC 27001:2022 certification applicable to its SOC/managed security services and valid ISO 9001 certification; both subject to online verification by NHBRC.
Key personnel must include a Project Manager (NQF 7, PMP/PRINCE2/CSM, 5 years ISO 27001 experience), CISO (NQF 7 ICT, CISSP/CISM/CASP+, 5 years cybersecurity management), SOC Lead (NQF 7, Security+/CySA+/CEH, 5 years SOC experience), and Cyber Security Architect (NQF 7, CISSP/CISM/CCSP/SABSA/TOGAF/Microsoft Cybersecurity Architect Expert/GIAC, 5 years experience); abridged CVs with certifications required for each.
Mandatory live SOC demonstration (Stage 2B, 20 points) using bidder's own operational SOC environment; must demonstrate live SIEM/XDR dashboard, active incident workflows, analyst investigation, SOC escalation/reporting, endpoint/identity controls, vulnerability management, and compliance reporting; minimum 10/20 points required; failure to participate or demonstrate a non-operational environment results in disqualification.
Minimum functionality threshold: 80/100 combined (Stage 2A ≥60/80 plus Stage 2B ≥10/20) to proceed to price evaluation.
Price evaluation uses 80/20 preference points system (services ≤ R50 million); preference points: women 12, youth 6, disabilities 2, military veterans 0.
SOC must be fully operational within South Africa; all analyst access to NHBRC monitoring data, alerts, and incident case information must be performed from within South Africa unless explicitly approved in writing by NHBRC.
Bid validity period: 90 days from closing date.
Clarification deadline: 03 September 2026; enquiries to Mr Kabelo Phalane at [email protected] or [email protected].
Continue with tenders sharing this issuer, category, or province.
Return to this tender’s issuing organisation, province, or category.
Continue with tenders sharing this issuer, category, or province.
Date & Time
Thursday, 10 September 2026 - 11:00
Venue
https://teams.microsoft.com/l/meetup-join/19%3ameeting_YTVjZDdkMDctZjc4OS00NjQ1LTgxMTAtNjZjYzY0YWEzY
Request for Bid(Open-Tender)
27 Leeuwkop - Sandton - Sunninghill - 2191
Tenders in this industry often require registration with these bodies.
Recommended Certifications
Having these can improve your winning chances: CA(SA) - Chartered Accountant, PMI-PMP (Project Management Professional), Prince2 Practitioner, Six Sigma Certification
AI Document Analysis Stages
Description
Source: Pricing Schedule Managed Cybersecurity.pdf (unknown)19 Aug
2026
Tender Published
Tender was published
10 Sept
2026
Closing Date
Tender closing date
These references help suppliers understand the public-procurement framework around this opportunity. They are generated from the tender category, issuing organisation type and procurement context.
These rules commonly apply to South African public-sector procurement.
Act 53 of 2003
Provides the empowerment-compliance context often used in public-sector supplier evaluation.
Relevant because this is a South African public-sector procurement opportunity.
Act 108 of 1996 (s217)
This is general procurement context, not legal advice. Always verify requirements in the official tender documents and issuing authority notices.
14. e-Submission_User Manual For Suppliers (1).pdf
The National Home Builders Registration Council invites proposals for the appointment of a Managed Cybersecurity Services Provider for a period of five (05) years. Bids must be submitted electronically via the eTender Portal at https://etenders.gov.za. The closing date is Thursday, 10 September 2026 at 11:00 (GMT+2).
Pricing Schedule Managed Cybersecurity.pdf
The National Home Builders Registration Council (NHBRC) is procuring a managed cybersecurity services provider for a five-year contract. The scope covers a 24/7 Security Operations Centre (SOC), SIEM/SOAR, EDR/XDR, vulnerability management, penetration testing, incident response, threat intelligence, exposure management, cyber awareness, and document security, with mandatory compliance to ISO/IEC 27001 and alignment to NIST CSF.
SBD-FORMS 1 4 3.1 6.1 (002).pdf
The National Home Builders Registration Council (NHBRC) invites proposals for the appointment of a Managed Cybersecurity Services Provider for a five-year period. The bid is subject to the Preferential Procurement Policy Framework Act and requires bidders to complete standard SBD forms, including pricing and preference points claims.
NHBRC RFP 01 2026 Cybersecurity_ (002).pdf
The National Home Builders Registration Council (NHBRC) seeks to appoint a managed cybersecurity services provider (MCSP) for five years to deliver comprehensive, end-to-end security services, including a 24/7/365 SOC, incident response, vulnerability management, and governance support, across its national network of offices. The contract will be governed by the 80/20 preference points system under the Preferential Procurement Regulations, 2022.
To download these documents and access AI-powered analysis, visit the main tender page.
Matched by category & region
Free guidance to prepare before you bid
Not sure if your business is ready for this tender? Check CSD, CIDB, and B-BBEE requirements, run a readiness assessment, and move from opportunity to submission.
Open Supplier Readiness HubLearn how to submit a winning bid with these related articles
Median Estimate
R 669 185
Range
Based on 25 comparable awarded tenders. Companies with similar profiles typically bid near the median.
* Estimates are based on historical data and do not guarantee actual award values.
We refine every tender document through these stages so you can brief your team and prepare your bid with confidence. Anything marked as "in progress" will be upgraded automatically — no action required from you.
This Glossary defines key technical, operational, and governance terms used throughout the Terms of Reference (TOR) and associated Annexures. The Glossary is intended to e
Instruction on Placement in the TOR
Placement Recommendation:
This Glossary must be included as Annexure G and referenced explicitly in:
The Introduction section of the TOR (e.g. "Definitions and Acronyms used in this TOR are provided in Annexure G").
Annexure A (Technical Requirements) to avoid repetitive explanations.
The Glossary must be treated as a normative reference, i.e. definitions apply wherever the terms are used in the TOR and Annexures.
A. General & Governance Terms
Acceptable Use Policy (AUP) – A policy defining acceptable and prohibited use of NHBRC systems, data, and devices.
Audit Trail – A chronological record of activities enabling reconstruction, review, and examination of events or transactions.
Compliance – Adherence to applicable laws, regulations, standards, and NHBRC internal policies including POPIA and PFMA.
Defence-in-Depth – A layered security strategy using multiple complementary security controls across people, process, and technology.
Evidence – Objective proof provided by a bidder to demonstrate compliance with a TOR requirement (e.g. certificates, reports, diagrams).
Governance – Structures, policies, and processes that ensure cybersecurity activities align with NHBRC strategy and regulatory obligations.
B. SOC, Monitoring & Response
Terms
Security Operations Centre (SOC) – A centralised function responsible for continuous monitoring, detection, analysis, and response to cybersecurity threats.
SOC 2 Type II – An independent assurance report assessing the design and operating effectiveness of controls over a defined period.
SIEM (Security Information and Event Management) – Technology that collects, correlates, and analyses security log data.
SOAR (Security Orchestration, Automation and Response) – Technology enabling automated workflows, playbooks, and response actions.
Use Case – A defined detection or response scenario describing a specific threat, risk, or malicious behaviour.
Runbook / Playbook – Documented procedures describing analyst or automated actions to be performed during defined security events.
MTTD (Mean Time to Detect) – Average time taken to identify a security incident from the point of occurrence.
MTTR (Mean Time to Respond/Recover) – Average time taken to contain or remediate a security incident after detection.
C. Threat, Risk & Exposure Terms
Threat Intelligence (TI) – Evidence-based information about existing or emerging threats, threat actors, and attack techniques.
Indicator of Compromise (IOC) – Observable artefacts indicating potential malicious activity (e.g. IP addresses, hashes).
Indicator of Attack (IOA) – Behavioural indicators suggesting malicious intent or activity.
MITRE ATT&CK – A globally recognised knowledge base describing adversary tactics, techniques, and procedures.
Exposure Management – Continuous identification, prioritisation, and remediation of attack paths, vulnerabilities, and misconfigurations.
ASM (Attack Surface Management) – Discovery and monitoring of internet-facing assets and exposures.
CTEM (Continuous Threat Exposure Management) – A risk-driven approach combining ASM, vulnerability management, and attack-path analysis.
D. Vulnerability & Testing Terms
Vulnerability – A weakness that can be exploited to compromise confidentiality, integrity, or availability.
Vulnerability Assessment (VA) – Systematic identification and analysis of vulnerabilities in systems and applications.
Penetration Testing (PT) – Controlled exploitation of vulnerabilities to assess security effectiveness.
CVSS (Common Vulnerability Scoring System) – An open standard for severity rating of vulnerabilities.
E. Identity, Access & Data Protection Terms
Identity and Access Management (IAM) – Processes and technologies managing digital identities and access rights.
Privileged Access Management (PAM) – Controls governing high-risk administrative and privileged accounts.
JIT / JEA (Just-In-Time / Just-Enough-Access) – Time-bound and least-privileged access control mechanisms.
Multi-Factor Authentication (MFA) – Authentication using two or more independent credential factors.
Data Loss Prevention (DLP) – Controls designed to prevent unauthorised disclosure of sensitive information.
Document Security – Encryption, access control, and audit logging applied at document level.
F. Awareness & Human Risk Terms
Cyber Awareness Programme – Structured training and behavioural initiatives aimed at reducing human-related cyber risk.
Phishing Simulation – Controlled testing of user susceptibility to phishing techniques.
Human Risk Metrics – Measurements such as click rate, report rate, and repeat offender rate used to assess awareness effectiveness.
G. Legal & Regulatory Terms
POPIA – Protection of Personal Information Act, 2013.
PFMA – Public Finance Management Act, 1999.
ISO/IEC 27001 – International standard for information security management systems.
NIST CSF – National Institute of Standards and Technology Cybersecurity Framework.
Maintenance
The MSSP must review and update this Glossary annually or when new technologies, services, or terms are introduced.
Important Dates
Source: Pricing Schedule Managed Cybersecurity.pdf (unknown)Submission Guidelines
Source: Pricing Schedule Managed Cybersecurity.pdf (unknown)Returnable documents — all must be completed, signed and submitted with the bid:
Disqualification risks:
Evaluation Criteria
Source: Pricing Schedule Managed Cybersecurity.pdf (unknown)The evaluation is a two-stage process with a minimum qualifying score of 80 out of 100.
Stage 2A – Technical Evaluation (80 points):
Stage 2B – Live SOC Demonstration (20 points):
Technical Specifications
Source: Pricing Schedule Managed Cybersecurity.pdf (unknown)The successful bidder will provide a full suite of managed cybersecurity services for five years. Key requirements include:
Methodology
Source: Pricing Schedule Managed Cybersecurity.pdf (unknown)Methodology & Approach 20
delivery
Subtotal 80
Stage 2B – Live SOC Demonstration (20 Points)
Experience & Qualifications
Source: Pricing Schedule Managed Cybersecurity.pdf (unknown)A15 with relevant certifications Mandatory CVs, certification evidence
and experience.
Provide three (3) contactable
A16 reference letters for similar Mandatory Reference letters
Bidder Experience MSSP experience ≥ 5 years 10
Quality Management
Source: Pricing Schedule Managed Cybersecurity.pdf (unknown)Exposure Management
Threat Intelligence
Governance & Policy Support
Cyber Awareness & Training
Ad-hoc Services
Total (Excl. VAT)
VAT (15%)
Total (Incl. VAT)
NB: Bidders must include escalations for each year for the duration of the contract.
Annexure F: Glossary of Terms and Acronyms
Annexure F: Glossary of Terms and Acronyms
management and annual VA/PT methodology, sample
A6 Mandatory
penetration testing, including reports
retesting.
Cyber Awareness Programme – Structured training and behavioural initiatives aimed at reducing human-related cyber risk.
Phishing Simulation – Controlled testing of user susceptibility to phishing techniques.
Human Risk Metrics – Measurements such as click rate, report rate, and repeat offender rate used to assess awareness effectiveness.
Pricing Schedule
Source: Pricing Schedule Managed Cybersecurity.pdf (unknown)Annexure E: Pricing Schedule
Annexure E: Pricing Schedule
(All prices VAT inclusive, in ZAR)
Cost Category Year 1 Year 2 Year 3 Year 4 Year 5 Total
Financial Requirements
Source: Pricing Schedule Managed Cybersecurity.pdf (unknown)Compliance Requirements
Source: Pricing Schedule Managed Cybersecurity.pdf (unknown)Health & Safety
Source: Pricing Schedule Managed Cybersecurity.pdf (unknown)be attached to the bid. Failure to provide a signed pricing schedule will result in disqualification.
amendments will be accepted after submission of the bid.
13th month, based on the average Consumer Price Index (CPI) as published by Stats SA.
Currency and VAT: All prices must be quoted in South African Rand (ZAR) and must be VAT inclusive.
Travel and Accommodation: The bidder is responsible for all travel and accommodation costs incurred during the execution of the contract, unless otherwise
agreed in writing by NHBRC.
Pricing Table: Bidders must complete the pricing schedule below. All prices must be VAT inclusive.
Threat Intelligence (TI) – Evidence-based information about existing or emerging threats, threat actors, and attack techniques.
Indicator of Compromise (IOC) – Observable artefacts indicating potential malicious activity (e.g. IP addresses, hashes).
Indicator of Attack (IOA) – Behavioural indicators suggesting malicious intent or activity.
MITRE ATT&CK – A globally recognised knowledge base describing adversary tactics, techniques, and procedures.
Exposure Management – Continuous identification, prioritisation, and remediation of attack paths, vulnerabilities, and misconfigurations.
ASM (Attack Surface Management) – Discovery and monitoring of internet-facing assets and exposures.
CTEM (Continuous Threat Exposure Management) – A risk-driven approach combining ASM, vulnerability management, and attack-path analysis.
Section
Source: Pricing Schedule Managed Cybersecurity.pdf (unknown)Annexure C: Evaluation Scoring Matrix (weighted)
Annexure C: Evaluation Scoring Matrix
Stage 2A – Technical Evaluation (80 Points)
Relevance & quality of
Stage 2B – Live SOC Demonstration (20 Points)
Minimum qualifying score: 80 / 100
Detection Quality False Positive Rate ≤ 15% SOC analytics Quarterly
nical Evaluation (80 Points)
Submission Guidelines
Source: 14. e-Submission_User Manual For Suppliers (1).pdf (TENDER)Bids must be submitted electronically via the eTender Portal (https://etenders.gov.za). Bidders must log in using their CSD-registered email address and password, select the relevant supplier number, and upload all required documents under the correct response document headings. Only one document can be uploaded per heading; the most recent upload is saved. After uploading, confirm and proceed, ensure the submission checklist is fully ticked, then click 'Submit now'. A successful submission is confirmed by a pop-up and the status changes to 'Submitted'. A 'Pending' status means required documents are still missing. Bids can be edited or withdrawn before the closing time; the edit function is disabled once the tender closes.
Evaluation Criteria
Source: 14. e-Submission_User Manual For Suppliers (1).pdf (TENDER)No evaluation criteria are stated in the document provided. Bidders must be registered on the Central Supplier Database (CSD) and have a registered supplier number on the eTender Portal to apply.
Compliance Requirements
Source: 14. e-Submission_User Manual For Suppliers (1).pdf (TENDER)Bidders must be registered on the Central Supplier Database (CSD) and must log in using the CSD-registered email address and password. A valid CSD supplier number is required to apply.
Description
Source: SBD-FORMS 1 4 3.1 6.1 (002).pdf (TENDER)The tender is for the appointment of a managed cybersecurity services provider for a period of five (05) years. Bids must be submitted online via the eTender portal.
Important Dates
Source: SBD-FORMS 1 4 3.1 6.1 (002).pdf (TENDER)Closing date: 10 September 2026. Closing time: 11:00.
Contact Information
Source: SBD-FORMS 1 4 3.1 6.1 (002).pdf (TENDER)Bidding procedure enquiries and technical enquiries may be directed to the contact persons listed in the bid document, with telephone, facsimile, and e-mail addresses provided. No specific contact details are given in the available text.
Submission Guidelines
Source: SBD-FORMS 1 4 3.1 6.1 (002).pdf (TENDER)Bids must be submitted online via the eTender portal at https://www.etenders.gov.za/. Bids must be delivered by the stipulated time; late bids will not be accepted. All bids must be submitted on the official forms provided, not re-typed. The successful bidder will be required to sign a written contract form (SBD 7). Returnable forms include: SBD 1 (Invitation to Bid), SBD 4 (Bidder's Disclosure), SBD 3.1 (Pricing Schedule – Firm Prices), and SBD 6.1 (Preference Points Claim Form). Proof of authority to sign (e.g., company resolution) must be submitted.
Returnable Documents
Source: SBD-FORMS 1 4 3.1 6.1 (002).pdf (TENDER)Bids must be delivered by the stipulated time to the correct address; late bids will not be accepted. All bids must be submitted on the official forms provided, not re-typed. The successful bidder will be required to fill in and sign a written contract form (SBD 7).
Evaluation Criteria
Source: SBD-FORMS 1 4 3.1 6.1 (002).pdf (TENDER)The applicable preference point system is the 90/10 system. Points are awarded for Price and Specific Goals, with a total of 100 points. The maximum points for price are 90, and for specific goals are 10. Failure to submit proof or documentation for specific goals means no preference points are claimed for those goals. The organ of state may require substantiation of any preference claim at any time.
Technical Specifications
Source: SBD-FORMS 1 4 3.1 6.1 (002).pdf (TENDER)The tender is for the appointment of a managed cybersecurity services provider for a period of five (05) years. The scope of services is not detailed in the available document.
Pricing Schedule
Source: SBD-FORMS 1 4 3.1 6.1 (002).pdf (TENDER)Pricing must be on a firm prices basis only; non-firm prices (including those subject to rate of exchange variations) will not be considered. The bid price must be in RSA currency and include all applicable taxes. All delivery costs must be included in the bid price. The offer must be valid for a specified number of days from the closing date. If different delivery points influence pricing, a separate pricing schedule must be submitted for each delivery point.
Financial Requirements
Source: SBD-FORMS 1 4 3.1 6.1 (002).pdf (TENDER)Pricing must be on a firm price basis only; non-firm prices (including those subject to rate of exchange variations) will not be considered. The pricing schedule (SBD 3.1) requires the bid price in RSA currency, including all applicable taxes. All delivery costs must be included in the bid price. The offer must be valid for a specified number of days from the closing date (to be stated by the bidder).
Compliance Requirements
Source: SBD-FORMS 1 4 3.1 6.1 (002).pdf (TENDER)Bidders must be registered on the Central Supplier Database (CSD) or provide a SARS Tax Compliance Status (TCS) PIN. Each party in a consortium/joint venture/sub-contractor must submit a separate TCS certificate/PIN/CSD number. Bidders must not be listed in the Register for Tender Defaulters or the List of Restricted Suppliers. Bidders must not be persons in the service of the state, nor companies/close corporations with directors/members who are persons in the service of the state. Bidders must disclose any relationship with any person employed by the procuring institution (NHBRC). Bidders must disclose all CSD-registered active companies linked to all directors; failure to do so leads to disqualification. Bidders must submit a B-BBEE status level verification certificate or sworn affidavit (for EMEs & QSEs) to claim preference points. The bid is subject to the Preferential Procurement Policy Framework Act, 2000 and the Preferential Procurement Regulations, 2017.
B-BBEE Requirements
Source: SBD-FORMS 1 4 3.1 6.1 (002).pdf (TENDER)A B-BBEE status level verification certificate or sworn affidavit (for EMEs & QSEs) must be submitted in order to qualify for preference points for B-BBEE.
Contractual Terms
Source: SBD-FORMS 1 4 3.1 6.1 (002).pdf (TENDER)The successful bidder will be required to sign a written contract form (SBD 7). The contract is subject to the General Conditions of Contract (GCC) and any special conditions of contract. The contract period is five (05) years.
Requirements
Source: SBD-FORMS 1 4 3.1 6.1 (002).pdf (TENDER)Bidders must ensure compliance with their tax obligations. Bidders must submit their unique SARS Tax Compliance Status (TCS) PIN or CSD number. Bidders must not be persons in the service of the state, nor companies/close corporations with directors/members who are persons in the service of the state. Bidders must not be listed in the Register for Tender Defaulters or the List of Restricted Suppliers.
Section
Source: SBD-FORMS 1 4 3.1 6.1 (002).pdf (TENDER)Bidding procedure and technical enquiries may be directed to the contact persons, telephone numbers, facsimile numbers, and e-mail addresses provided in the bid document. No specific contact details are available in the provided text.
Description
Source: NHBRC RFP 01 2026 Cybersecurity_ (002).pdfThe NHBRC is a regulator established under the Housing Consumers Protection Measures Act, 1998, mandated to regulate the home building industry and protect housing consumers. It has approximately 620 employees, with head office in Sunninghill, Gauteng, and nine provincial and 12 satellite offices across South Africa. The NHBRC is on a digital transformation journey and seeks to appoint a Managed Cybersecurity Services Provider for five years to deliver comprehensive, end-to-end cybersecurity services across its national network of offices, strengthening security posture, ensuring compliance with ISO/IEC 27001, POPIA, PFMA, and improving cybersecurity maturity.
Important Dates
Source: NHBRC RFP 01 2026 Cybersecurity_ (002).pdf (RFP)RFP documents available from: 19 August 2026 (NHBRC website and eTender Portal).
Non-compulsory virtual briefing session: 28 August 2026 at 11:00 via Microsoft Teams (link provided in RFP). Bidders struggling to connect should email [email protected] before 11:00 to request an invite.
Clarification deadline: 03 September 2026 (responses communicated weekdays 08:30–16:30).
Closing date and time: 10 September 2026 at 11:00 (online submission only).
Bid validity period: 90 days from closing date.
Briefing Session
Source: NHBRC RFP 01 2026 Cybersecurity_ (002).pdf (RFP)A non-compulsory virtual briefing session will be held on 28 August 2026 at 11:00 via Microsoft Teams. The link is provided in the RFP. Bidders who struggle to connect should email [email protected] before 11:00.
Contact Information
Source: NHBRC RFP 01 2026 Cybersecurity_ (002).pdf (RFP)Administrative enquiries: Mr Kabelo Phalane, Supply Chain Management.
Email: [email protected] or [email protected].
Clarifications must be submitted by 03 September 2026.
Responses communicated on weekdays between 08:30 and 16:30.
Submission Guidelines
Source: NHBRC RFP 01 2026 Cybersecurity_ (002).pdf (RFP)Bids must be submitted online via the National Treasury eTender Portal (https://www.etenders.gov.za/) in PDF format, marked for the attention of the Supply Chain Manager, on or before 10 September 2026 at 11:00. No physical or emailed proposals will be accepted; late submissions are rejected.
Returnable documents (all must be completed, signed and submitted):
Disqualification risks:
The NHBRC reserves the right to amend, modify, or withdraw the RFP at any time without notice. Bids must remain valid for 90 days. No entity may be involved in more than one bid. Material changes in bidder control require prior written approval. The NHBRC may waive irregularities at its discretion. Bidders may be required to give a formal presentation. The NHBRC may conduct due diligence, negotiate with shortlisted bidders, and reserves the right not to make an award.
Returnable Documents
Source: NHBRC RFP 01 2026 Cybersecurity_ (002).pdf (RFP)Bidders must submit SBD 1 (Invitation to Bid), SBD 3.1 (Pricing Schedule), SBD 6.1 (Preference Claim Form), CSD report, CIPC documents, SARS PIN, signed teaming agreement, and certified ID documents of directors. Additionally, a detailed technical proposal, company profile, CVs of key personnel, reference letters, and project plan must be submitted.
Evaluation Criteria
Source: NHBRC RFP 01 2026 Cybersecurity_ (002).pdf (RFP)Evaluation is in three stages:
Stage 1: Compliance check of mandatory administrative and legislative documents. Failure to submit mandatory documents results in disqualification.
Stage 2: Functional evaluation in two parts:
Final Technical Score = Stage 2A + Stage 2B (max 100). Minimum 80/100 to proceed to Stage 3.
Stage 3: Price and preference points using the 80/20 system (services ≤ R50 million). Price points calculated as PS = 80(1 - Pt/Pmin), rounded to two decimals. Preference points: women 12, youth 6, disabilities 2, military veterans 0 (total 20).
Technical Specifications
Source: NHBRC RFP 01 2026 Cybersecurity_ (002).pdf (RFP)The NHBRC seeks a Managed Cybersecurity Services Provider (MCSP) for a five-year period to deliver end-to-end cybersecurity services across its national network (head office in Sunninghill, Gauteng; 9 provincial and 12 satellite offices).
Current environment (indicative):
Scope of works (detailed in Annexure A):
Deliverables: onboarding pack, operational artefacts, reporting (daily/weekly summaries, monthly KPI and risk posture report, quarterly executive maturity report), assurance outputs, testing outputs, training outputs.
Service level KPIs (minimum):
SOC location and data sovereignty: SOC must be fully operational within South Africa; all analyst access to NHBRC data must be from within South Africa unless explicitly approved in writing.
Methodology
Source: NHBRC RFP 01 2026 Cybersecurity_ (002).pdfBidders must submit a detailed project proposal outlining implementation and transition to managed services, including implementation phases and milestones, platform onboarding and integration approach, risk and change management approach, and knowledge transfer and capacity-building plan. The migration plan must include objectives, scope, timelines, resources, risk management, work breakdown structure, methodology, process flows, six-month timelines, and deliverables relevant to NHBRC requirements. Bidders must acknowledge that some activities may be required outside normal business hours to avoid disruption to NHBRC operations.
Experience & Qualifications
Source: NHBRC RFP 01 2026 Cybersecurity_ (002).pdfBidders must have a minimum of five years' proven experience delivering enterprise-grade managed cybersecurity services, including servicing public sector entities or similarly regulated organisations within South Africa. They must demonstrate operational capability to provide 24/7/365 SOC services. Key personnel must hold relevant certifications (CISSP, CISM, GCIH/GCFA, OSCP, Microsoft Security Certifications) and have experience in SOC operations, incident response and digital forensics, network and cloud security (Microsoft Azure), identity and access management, and governance, risk and compliance. At least three contactable reference letters from similar MCSSP engagements must be provided on the client's official letterhead, signed by an authorised representative, confirming scope and duration, and including client contact details. Reference letters must relate to cybersecurity services of similar scope and complexity to the NHBRC requirement.
Quality Management
Source: NHBRC RFP 01 2026 Cybersecurity_ (002).pdfBidders must hold valid ISO/IEC 27001:2022 certification applicable to their managed security services/SOC environment and ISO 9001 certification for quality management. The bidder must demonstrate alignment with recognised cybersecurity frameworks, including NIST Cybersecurity Framework and/or COBIT. The NHBRC will verify certifications online.
Pricing Schedule
Source: NHBRC RFP 01 2026 Cybersecurity_ (002).pdfThe pricing schedule (SBD 3.1) must be completed and signed, including a detailed cost breakdown and escalation per annum. It must be signed by the bidder or an authorised individual with a resolution attached; if not signed, the bidder is disqualified. The 80/20 preference points system applies, with price scored using the formula PS = 80(1 - Pt/Pmin). Preference points: women 12, youth 6, disabilities 2, military veterans 0.
Financial Requirements
Source: NHBRC RFP 01 2026 Cybersecurity_ (002).pdf (RFP)Pricing schedule (SBD 3.1) must be completed and signed, including a detailed cost breakdown and escalation per annum. Must be signed by the bidder or an authorised individual with a resolution attached; if not signed, the bidder is disqualified.
Cyber Security Professional Indemnity and/or Cyber Liability Insurance with a minimum coverage of R10,000,000.00 (Ten Million Rand) is mandatory. A certified copy of the insurance certificate or policy schedule must be provided and remain valid for the full contract duration, with evidence of renewal provided to the NHBRC.
Price evaluation uses the 80/20 preference points system (services valued at not more than R50 million). Price points are calculated using the formula PS = 80(1 - Pt/Pmin), rounded to two decimal places. Preference points: women 12, youth 6, disabilities 2, military veterans 0, total 20 points.
Compliance Requirements
Source: NHBRC RFP 01 2026 Cybersecurity_ (002).pdf (RFP)CSD registration: bidders must be registered on the National Treasury's Central Supplier Database and remain registered with up-to-date information for the contract duration.
Tax compliance: bidders must be tax compliant at bid submission and for the contract duration, providing a SARS Tax Clearance Certificate annually.
Mandatory certifications:
Cyber insurance: minimum R10,000,000.00 Cyber Security Professional Indemnity and/or Cyber Liability Insurance.
Legislative documents (not for disqualification but required): SBD 1, SBD 3.1, SBD 6.1, CSD report/MAAA number, latest CIPC documents, valid SARS PIN, signed teaming agreement, certified ID documents of directors.
B-BBEE: preference points are claimed under the 80/20 system via SBD 6.1, with points for women (12), youth (6), disabilities (2), and military veterans (0).
Contract management: General Conditions of Contract (GCC) as issued by National Treasury and a Service Level Agreement (SLA). Bids must remain valid and irrevocable for 90 days from closing date. The NHBRC may amend, modify or withdraw the RFP at any time without notice. No entity may be involved in more than one bid. Material changes in bidder control or composition after submission require prior written NHBRC approval. The NHBRC may waive irregularities at its discretion. Bidders may be required to give a formal presentation at their own cost. The NHBRC may conduct due diligence, negotiate with shortlisted bidders, and reserves the right not to make an award. The successful bidder must maintain confidentiality of NHBRC data and comply with data sovereignty requirements. The NHBRC may terminate the contract for misrepresentation or non-compliance.
Requirements
Source: NHBRC RFP 01 2026 Cybersecurity_ (002).pdf (RFP)Bidders must be registered on the CSD, be tax compliant, and provide a SARS Tax Clearance Certificate annually. Bidders must have a minimum of five years' proven experience delivering enterprise-grade managed cybersecurity services, demonstrate operational capability to provide 24/7/365 SOC services, hold valid ISO/IEC 27001:2022 and ISO 9001 certifications, provide at least three contactable reference letters, and disclose SOC location and data handling practices. Mandatory documents include a signed pricing schedule, SBD 4, ISO 27001 and ISO 9001 certificates, and cyber liability insurance of at least R10 million. Bidders must provide proof of OEM certifications/authorised reseller agreements for security technologies (SIEM/XDR, EDR, network/perimeter security, cloud security platforms).
Section
Source: NHBRC RFP 01 2026 Cybersecurity_ (002).pdfEvaluation is in three stages: Stage 1 compliance check, Stage 2 functional evaluation (Stage 2A paper-based 80 points, Stage 2B live SOC demonstration 20 points), and Stage 3 price and preference points. Bidders must achieve a minimum of 80 points out of 100 in Stage 2 to proceed. Stage 2A evaluates bidder experience (10), client references (20), project team capability (30), and migration plan (20). Stage 2B is a mandatory live SOC demonstration. Stage 3 uses the 80/20 preference points system, with 20 points for preference (women 12, youth 6, disabilities 2, military veterans 0).
Sets the constitutional standard for fair, equitable, transparent, competitive and cost-effective public procurement.
Relevant because this is a South African public-sector procurement opportunity.
Act 5 of 2000
Covers preferential procurement and preference-point systems used in public tenders.
Relevant because this is a South African public-sector procurement opportunity.
Act 12 of 2004
Supports anti-corruption controls and supplier integrity in procurement processes.
Relevant because this is a South African public-sector procurement opportunity.
Act 28 of 2024
Provides the national framework for public procurement across government.
Relevant because this is a South African public-sector procurement opportunity.
Act 2 of 2000
Supports access to tender records, award decisions and public-sector procurement information.
Relevant because this is a South African public-sector procurement opportunity.
Act 3 of 2000
Supports lawful, reasonable and procedurally fair administrative tender decisions.
Relevant because this is a South African public-sector procurement opportunity.
Address
27 Leeuwkop Road Sandton, Sunninghill, Johannesburg, 2157, South Africa
Source confidence
High source confidence
Official source
eTenders.gov.za
Documents found
4
Last checked
19 Aug 2026
AI status
Enhanced
Data conflicts
None detected
This tender has strong source evidence, including source metadata and supporting tender information synced from the government tender portal.
Tenders SA is not the issuing authority. All tenders are automatically synced from the official government tender portal. Always confirm final submission details, closing dates, briefing sessions, eligibility requirements, and documents on the official government portal before applying.
Contact
011-317-0114[email protected]www.nhbrc.org.za27 Leeuwkop Road Sandton, Sunninghill, Johannesburg, 2157, South Africa
Key Personnel
Provinces Active
Industries
💡 Want more tendering tips and strategies?
Explore Our BlogGet deep intelligence on Computer programming, consultancy and related activities. Unlock full pricing strategies, bid frequency, and historical win rates.