Broad-Based Black Economic Empowerment Act (B-BBEE Act)
Act 53 of 2003
Provides the empowerment-compliance context often used in public-sector supplier evaluation.
Relevant because this is a South African public-sector procurement opportunity.
Issuing Organization
Council for Scientific and Industrial Research (CSIR)Location
Gauteng
Closing Date
04 Sept 2026
Documents available on tender detail page
Tender Type
Request for Proposal
Delivery Location
627 Meiring Naude Road - Brummeria - Pretoria - 0184
Organization Type
GOVERNMENT
Published
21 Aug 2026
OCDS Reference
ocds-9t57fa-166536
The csir is procuring the provision of capture the flag (ctf) challenges for a student competition, with submissions due on 04 march 2025 at 11h00. Bidders must have experience in cybersecurity education, ctf design, and running competitions. The required deliverables include 40 custom ctf challenges at different difficulty levels, a dedicated competition platform with anti-cheat capabilities, and on-site support during the final event. Bid evaluation is in three phases: eligibility, technical (80% pass mark), and price/preference (80/20 points). Mandatory documents include sbd forms, pricing schedule, tax compliance, csd registration, and signed declarations. Submissions must be electronic to the specified address.
Provide 64 CTF challenges: 40 for the Qualification event and 24 for the Final event.
Cover all 10 required CTF categories in the supplied challenges (scoring: 10 for all 10, 5 for 6β9, 0 for 5 or fewer).
Deliver challenges directly; if using subcontracting, joint venture or consortium, provide the agreements required under Section 3.1.4 β direct supply scores 10, subcontracted supply scores 0.
Confirm that challenge difficulty levels (easy, medium, hard) meet the minimum criteria in Section 3.1.5.
Provide 6 bespoke CTF challenges (4 medium and 2 hard) for the Final event, not available on the internet.
Supply step-by-step solutions with each challenge.
Ensure all challenges are compatible with the SANReN platform β the ITOCA Platform (hosted by CSIR).
Provide remote technical support for the Qualification event and in-person technical support for the Final event, and confirm the support provider is the party that developed the challenges.
Provide sample challenges as part of the bid submission.
Bidders must ensure the party providing remote technical support is the same party that developed the challenges.
Continue with tenders sharing this issuer, category, or province.
Return to this tenderβs issuing organisation, province, or category.
Continue with tenders sharing this issuer, category, or province.
Date & Time
Friday, 04 September 2026 - 16:30
Venue
MS TEAMS LINK
Request for Proposal
627 Meiring Naude Road - Brummeria - Pretoria - 0184
Tenders in this industry often require registration with these bodies.
Recommended Certifications
Having these can improve your winning chances: CA(SA) - Chartered Accountant, PMI-PMP (Project Management Professional), Prince2 Practitioner, Six Sigma Certification
AI Document Analysis Stages
Description
21 Aug
2026
Tender Published
Tender was published
04 Sept
2026
Closing Date
Tender closing date
These references help suppliers understand the public-procurement framework around this opportunity. They are generated from the tender category, issuing organisation type and procurement context.
These rules commonly apply to South African public-sector procurement.
Act 53 of 2003
Provides the empowerment-compliance context often used in public-sector supplier evaluation.
Relevant because this is a South African public-sector procurement opportunity.
Act 108 of 1996 (s217)
This is general procurement context, not legal advice. Always verify requirements in the official tender documents and issuing authority notices.
RFP 6753-04-09-2026 Capture the Flag challenges for SANReN Cyber Security Challenge.pdf
The CSIR is procuring 64 Capture the Flag (CTF) challenges, including solutions, for the SANReN Cyber Security Challenge 2026/27: 24 challenges for the 2026 final and 40 for the 2027 qualification round. The challenges must be delivered on a CTFd platform and cover at least six of ten specified cybersecurity categories. Bidders must submit a technical proposal, sample challenges, and a pricing schedule, with evaluation based on technical criteria (80% minimum), price, and preference points.
Annexure_C1_-_Technical_Evaluation_Matrix RFP 6753-04-09-2026.xlsx
The CSIR, on behalf of SANReN, is procuring Capture the Flag (CTF) challenges for the SANReN Cyber Security Challenge 2026/27. The successful bidder must deliver 64 CTF challenges (40 for the Qualification event and 24 for the Final event), including bespoke challenges, solutions, and supporting items, and provide remote and in-person technical support.
To download these documents and access AI-powered analysis, visit the main tender page.
Matched by category & region
Free guidance to prepare before you bid
Not sure if your business is ready for this tender? Check CSD, CIDB, and B-BBEE requirements, run a readiness assessment, and move from opportunity to submission.
Open Supplier Readiness HubLearn how to submit a winning bid with these related articles
Median Estimate
RΒ 669Β 185
Range
Based on 25 comparable awarded tenders. Companies with similar profiles typically bid near the median.
* Estimates are based on historical data and do not guarantee actual award values.
π‘ Want more tendering tips and strategies?
Explore Our BlogGet deep intelligence on Other professional, scientific and technical activities. Unlock full pricing strategies, bid frequency, and historical win rates.
We refine every tender document through these stages so you can brief your team and prepare your bid with confidence. Anything marked as "in progress" will be upgraded automatically β no action required from you.
The procurement is for Capture the Flag (CTF) challenges to be used in the SANReN Cyber Security Challenge 2026/27. The scope includes designing, developing, and delivering CTF challenges for both qualification and final events, along with solutions, supporting items, and technical support.
Submission Guidelines
Source: Annexure_C1_-_Technical_Evaluation_Matrix RFP 6753-04-09-2026.xlsx (unknown)Bidders must complete the Technical Evaluation Matrix in full and adhere strictly to its format. The matrix is a summary; supporting documentation may be provided separately, with references to the applicable section per criterion. A score of 0 on any criterion results in failure. Proposals scoring below the pre-determined minimum overall percentage or below any specific minimum in the matrix will be eliminated. Returnable forms: none specified beyond the matrix itself. Disqualification risks: incomplete matrix, non-adherence to format, failure to respond to any criterion, or scoring 0 on any criterion.
Evaluation Criteria
Source: Annexure_C1_-_Technical_Evaluation_Matrix RFP 6753-04-09-2026.xlsx (unknown)Bidders must not score 0 on any technical criterion. They must achieve a minimum overall weighted technical score and meet each specific minimum in the Technical Compliance Matrix. Bidders must provide a portfolio of evidence of past CTF challenge provisioning, with signed reference letters for at least one event (three or more preferred). Bidders must not fail any criterion; a 'Do Not Comply' response on any criterion leads to failure. Bidders must confirm that the supply of CTF challenges is not licensed from a third party, or if subcontracted, must provide the required agreements. Bidders must confirm that the party providing technical support is the same party that developed the challenges.
Technical Specifications
Source: Annexure_C1_-_Technical_Evaluation_Matrix RFP 6753-04-09-2026.xlsx (unknown)The tender is for the procurement of Capture the Flag (CTF) challenges for the SANReN Cyber Security Challenge 2026/27. Deliverables: 64 CTF challenges total β 40 for the Qualification event and 24 for the Final event. Challenges must cover 10 required categories. Difficulty levels: easy, medium, hard, with a specified distribution. Bespoke (new) challenges required: 4 medium and 2 hard. Each challenge must include a step-by-step solution. Challenges must be compatible with the SANReN-implemented CTFd platform via CSV import or manual import. Supporting items must be supplied. Delivery method must be described (e.g., email, shared drive, external drive). Bidders must provide remote technical support for the Qualification event and in-person technical support for the Final event; the support provider must be the party that developed the challenges. Sample challenges required: 2 easy, 2 medium, and 2 hard, with solutions, in PDF format. Sample challenges must not be available on the Internet. Bidders must confirm alignment of sample challenge difficulty levels with minimum criteria.
Compliance Requirements
Source: Annexure_C1_-_Technical_Evaluation_Matrix RFP 6753-04-09-2026.xlsx (unknown)No specific compliance requirements (e.g., CSD, tax, B-BBEE, CIDB) are stated in the provided text.
Description
Source: RFP 6753-04-09-2026 Capture the Flag challenges for SANReN Cyber Security Challenge.pdfThis RFP is for the procurement of Capture the Flag (CTF) challenges for the SANReN Cyber Security Challenge 2026/27. The service includes all requirements in Annexure B. The National Integrated Cyber Infrastructure System (NICIS) hosts the CHPC National Conference annually. SANReN hosts its Cyber Security Challenge (CSC) for tertiary students as a parallel event. The competition has two rounds: an online Qualification Round (March to September) and an in-person Final Round at the CHPC National Conference (end November/start December).
Important Dates
Source: RFP 6753-04-09-2026 Capture the Flag challenges for SANReN Cyber Security Challenge.pdf (RFP)Closing date: Friday, 04 September 2026 at 16:30 (South African standard time).
Non-compulsory briefing: Friday, 28 August 2026, 11:00 β 12:30, via MS Teams.
Last date for enquiries/clarifications: Wednesday, 02 September 2026 at 16:30.
Contact Information
Source: RFP 6753-04-09-2026 Capture the Flag challenges for SANReN Cyber Security Challenge.pdf (RFP)All submissions and enquiries: [email protected].
Procurement Unit.
Use RFP number and description as subject reference.
CSIR business hours: 08:00 β 16:30, Monday to Friday.
No other contact with CSIR personnel is permitted during the RFP process.
Submission Guidelines
Source: RFP 6753-04-09-2026 Capture the Flag challenges for SANReN Cyber Security Challenge.pdf (RFP)Submit proposals electronically to [email protected]. Use the RFP number and description as the email subject. Send Technical Proposal and Pricing Proposal in two separate emails. Do not use cloud solutions (WeTransfer, Google Drive, Dropbox). Late proposals or those sent to the wrong address will not be considered. Proposals must be signed by an authorised person.
Returnable forms (all must be completed and signed):
Disqualification risks: any missing or unsigned mandatory returnable document, late submission, submission to incorrect email, counter conditions, or failure to comply with any term.
Returnable Documents
Source: RFP 6753-04-09-2026 Capture the Flag challenges for SANReN Cyber Security Challenge.pdf (RFP)Mandatory returnable documents as per Annexure E. Technical Proposal must include: company profile, portfolio of evidence confirming past experience developing and providing CTF challenges (including signed reference letters for at least one event, three or more preferred), technical proposal with details supporting compliance with evaluation criteria, completed Technical Evaluation Matrix (Annexure C1) in PDF and/or Excel, six sample challenges with solutions (2 hard, 2 medium, 2 easy) submitted separately, and if applicable, a legally valid and signed sub-contracting/joint venture/consortium agreement specifying required items (identification, scope of work, roles, technical support responsibility, error correction responsibility, risk mitigation or joint liability). Financial Proposal must include completed Pricing Schedule (Annexure D) on letterhead and CSD registration report (RSA suppliers only).
Evaluation Criteria
Source: RFP 6753-04-09-2026 Capture the Flag challenges for SANReN Cyber Security Challenge.pdf (RFP)Three-phase evaluation:
CSIR may award to a non-highest scorer per PPPFA Section 2(1)(f) if no fraud/illegal conduct charges.
Technical Specifications
Source: RFP 6753-04-09-2026 Capture the Flag challenges for SANReN Cyber Security Challenge.pdf (RFP)Scope: supply of Capture the Flag (CTF) challenges for the SANReN Cyber Security Challenge 2026/27, hosted on a CTFd platform.
Total challenges required: 64 (24 for the 2026 Final, 40 for the 2027 Qualification round).
Challenge categories: must cover at least 6 of: Web Exploitation, Cryptography, Forensics, Reverse Engineering, OSINT, Network Analysis, Binary Exploitation, Mobile Security, Steganography, Vulnerability Assessment.
Difficulty levels: Easy, Medium, Hard. Distribution: Qualification β 24 Easy, 8 Medium, 8 Hard; Final β 12 Easy, 6 Medium, 6 Hard.
Bespoke challenges: 4 of the 6 Medium and 2 of the 6 Hard challenges for the Final must be new (not previously used).
Bidder must resolve any errors in delivered challenges at no further cost.
No licensing of CTF challenges from third parties is allowed.
Supply of problem statements for hackathons will not be considered.
Methodology
Source: RFP 6753-04-09-2026 Capture the Flag challenges for SANReN Cyber Security Challenge.pdfProposals must be structured as two parts: Technical Proposal and Pricing Proposal, submitted in separate emails. Technical Proposal must include company profile, portfolio of evidence, technical proposal, completed Technical Evaluation Matrix (Annexure C1), sample challenges, and any required agreements. Pricing Proposal must include completed Pricing Schedule (Annexure D) on letterhead and CSD registration report.
Experience & Qualifications
Source: RFP 6753-04-09-2026 Capture the Flag challenges for SANReN Cyber Security Challenge.pdfBidders must submit a portfolio of evidence showing past experience provisioning CTF challenges for events, including dates, number and categories of challenges. Signed reference letters from event organisers are required for at least one event (three or more preferred). For sub-contracting/JV/consortium, reference letters confirming past collaboration between parties are required. Supply of problem statements for hackathons will not be considered.
Quality Management
Source: RFP 6753-04-09-2026 Capture the Flag challenges for SANReN Cyber Security Challenge.pdfCSIR may conduct inspections or audits of the bidder's compliance with POPI Act safeguards. No other quality management or QA/QC requirements stated.
Pricing Schedule
Source: RFP 6753-04-09-2026 Capture the Flag challenges for SANReN Cyber Security Challenge.pdfPricing must be submitted on Annexure D (Pricing Schedule/Bill of Quantities) on official company letterhead. Pricing must be in South African Rand including all taxes and unconditional discounts. Prices subject to escalation or exchange rate fluctuations must be clearly indicated. Price must include travel, freight, insurance, duty where applicable. Payment according to CSIR Payment Terms and Conditions.
Financial Requirements
Source: RFP 6753-04-09-2026 Capture the Flag challenges for SANReN Cyber Security Challenge.pdf (RFP)Pricing in South African Rand, including all taxes and unconditional discounts.
Prices subject to escalation or exchange rate fluctuations must be clearly indicated with currency and rate.
Price must include travel, freight, insurance, duty where applicable.
Payment according to CSIR Payment Terms and Conditions.
Pricing must be submitted on Annexure D (Pricing Schedule/Bill of Quantities) on official company letterhead.
No bond or guarantee percentage stated.
Compliance Requirements
Source: RFP 6753-04-09-2026 Capture the Flag challenges for SANReN Cyber Security Challenge.pdf (RFP)CSD registration: mandatory for RSA suppliers; provide CSD registration number. Foreign suppliers with no local entity need not register.
Tax compliance: bidders must be tax compliant. Provide SARS Tax Compliance Status PIN or TCS certificate. Non-compliant bidders have 7 working days to provide proof of compliance or arrangement.
B-BBEE: preference points claimed via Annexure G. Joint ventures must submit a consolidated B-BBEE scorecard.
No tender will be awarded to bidders on the NT Register of Tender Defaulters or List of Restricted Suppliers.
Joint ventures/consortia: must submit signed agreement, valid B-BBEE certificate, TCS/CSD report for each partner, proof of ownership, and company registration certificates.
No specific CIDB grade, CIPC registration, or professional-body registration required.
Contractual Terms
Source: RFP 6753-04-09-2026 Capture the Flag challenges for SANReN Cyber Security Challenge.pdfContract will be a Service Level Agreement (SLA) concluded after award. Bidders must comment on draft Service Level Indicators using track changes. CSIR may accept or reject amendments. Misrepresentation may lead to termination and damages. CSIR may terminate if funds are unavailable, paying for services delivered up to cancellation. South African law governs the contract. Bidders must comply with POPI Act for personal information. No goods/services delivered without a CSIR purchase order.
Special Conditions
Source: RFP 6753-04-09-2026 Capture the Flag challenges for SANReN Cyber Security Challenge.pdfCSIR reserves the right to: extend closing date, correct mistakes, verify submissions, request documentary proof, carry out site inspections/product evaluations, award to a bidder not scoring highest per PPPFA Section 2(1)(f), request audited financial statements, award in whole or part, award to multiple bidders, cancel/terminate the process at any stage, post-tender negotiate, and not award to a bidder associated with a security breach or whose directors are charged with fraud/illegal conduct.
Requirements
Source: RFP 6753-04-09-2026 Capture the Flag challenges for SANReN Cyber Security Challenge.pdf (RFP)Bidders must self-register on National Treasury's Central Supplier Database (CSD) and provide the CSD registration number. Bidders must not be listed on the NT database of restricted suppliers or the NT Register of Tender Defaulters. Bidders must be tax compliant. Joint ventures/consortia must submit signed agreements, B-BBEE certificates, TCS/CSD reports, proof of ownership, and company registration certificates.
Section
Source: RFP 6753-04-09-2026 Capture the Flag challenges for SANReN Cyber Security Challenge.pdf (RFP)All submissions and enquiries: [email protected]. Procurement Unit. Use RFP number and description as subject reference. Last date for enquiries/clarifications: Wednesday, 02 September 2026 at 16:30. CSIR business hours: 08:00 β 16:30.
Sets the constitutional standard for fair, equitable, transparent, competitive and cost-effective public procurement.
Relevant because this is a South African public-sector procurement opportunity.
Act 5 of 2000
Covers preferential procurement and preference-point systems used in public tenders.
Relevant because this is a South African public-sector procurement opportunity.
Act 12 of 2004
Supports anti-corruption controls and supplier integrity in procurement processes.
Relevant because this is a South African public-sector procurement opportunity.
Act 28 of 2024
Provides the national framework for public procurement across government.
Relevant because this is a South African public-sector procurement opportunity.
Act 2 of 2000
Supports access to tender records, award decisions and public-sector procurement information.
Relevant because this is a South African public-sector procurement opportunity.
Act 3 of 2000
Supports lawful, reasonable and procedurally fair administrative tender decisions.
Relevant because this is a South African public-sector procurement opportunity.
Address
Stellenbosch Central, Stellenbosch, 7600, South Africa
Source confidence
High source confidence
Official source
eTenders.gov.za
Documents found
2
Last checked
21 Aug 2026
AI status
Enhanced
Data conflicts
None detected
This tender has strong source evidence, including source metadata and supporting tender information synced from the government tender portal.
Tenders SA is not the issuing authority. All tenders are automatically synced from the official government tender portal. Always confirm final submission details, closing dates, briefing sessions, eligibility requirements, and documents on the official government portal before applying.
government organization in South Africa
Stellenbosch Central, Stellenbosch, 7600, South Africa