Broad-Based Black Economic Empowerment Act (B-BBEE Act)
Act 53 of 2003
Provides the empowerment-compliance context often used in public-sector supplier evaluation.
Relevant because this is a South African public-sector procurement opportunity.
Issuing Organization
National Home Builders Registration CouncilLocation
Gauteng
Closing Date
02 Oct 2026
Documents available on tender detail page
Tender Type
Request for Bid(Open-Tender)
Delivery Location
27 Leeuwkop - Sandton - Sunninghill - 2191
Organization Type
GOVERNMENT
Published
04 Sept 2026
OCDS Reference
ocds-9t57fa-168983
Managed infrastructure services are required by the national home builders registration council (nhbrc) for a period of two (05) years under reference nhbrc 08/2026. bidders must submit their proposals electronically through the etender portal. The most consequential requirement is that the correct supplier profile must be selected when applying, and all required documents must be uploaded for the bid to be successfully submitted.
Submission method: Bids must be submitted electronically via the eTender Portal at etenders.gov.za using the e-Submission process; the tender must be found under Currently Advertised and the eSubmission process started.
The bidder must log in using the CSD-registered email address and password.
The correct supplier number must be selected when starting the eSubmission response; only one document may be uploaded per response document heading.
The submission checklist must be fully ticked and the status must show as Submitted before the closing time; a Pending status means the bid has not been successfully submitted.
Edits or withdrawals must be done through the eSubmission portal before closing; the Edit and Withdraw functions are disabled once the tender closes.
Bids are submitted through the eTender Portal only; no postal, hand or email delivery is described.
The contract period is stated as two (05) years, as per the tender title.
Continue with tenders sharing this issuer, category, or province.
Return to this tender’s issuing organisation, province, or category.
Continue with tenders sharing this issuer, category, or province.
Date & Time
Friday, 02 October 2026 - 11:00
Venue
https://teams.microsoft.com/meet/362252380611593?p=A3aKrMazq1s4rr5C4p
Request for Bid(Open-Tender)
27 Leeuwkop - Sandton - Sunninghill - 2191
Tenders in this industry often require registration with these bodies.
Recommended Certifications
Having these can improve your winning chances: CA(SA) - Chartered Accountant, PMI-PMP (Project Management Professional), Prince2 Practitioner, Six Sigma Certification
AI Document Analysis Stages
Description
Source: NHBRC 08 2026 TOR Managed Infrastructure Solution 1.pdf (RFP)04 Sept
2026
Tender Published
Tender was published
02 Oct
2026
Closing Date
Tender closing date
These references help suppliers understand the public-procurement framework around this opportunity. They are generated from the tender category, issuing organisation type and procurement context.
These rules commonly apply to South African public-sector procurement.
Act 53 of 2003
Provides the empowerment-compliance context often used in public-sector supplier evaluation.
Relevant because this is a South African public-sector procurement opportunity.
Act 108 of 1996 (s217)
This is general procurement context, not legal advice. Always verify requirements in the official tender documents and issuing authority notices.
NHBRC 08 2026 TOR Managed Infrastructure Solution 1.pdf
Analysis completed but response format was invalid
e-Submission_User Manual For Suppliers.pdf
Managed infrastructure services for the National Home Builders Registration Council (NHBRC) for a period of five years, delivered through an e-submission process on the national eTender portal.
SBD FORMS_ 1 4 and 6.1. 3.1 .pdf
The National Home Builders Registration Council (NHBRC) invites proposals for a fully integrated managed infrastructure solution, to be delivered over a five-year period. The contract will be awarded through a competitive bidding process, with submissions made online via the eTender portal.
To download these documents and access AI-powered analysis, visit the main tender page.
Matched by category & region
Free guidance to prepare before you bid
Not sure if your business is ready for this tender? Check CSD, CIDB, and B-BBEE requirements, run a readiness assessment, and move from opportunity to submission.
Open Supplier Readiness HubMedian Estimate
R 593 538
Range
Based on 25 comparable awarded tenders. Companies with similar profiles typically bid near the median.
* Estimates are based on historical data and do not guarantee actual award values.
We refine every tender document through these stages so you can brief your team and prepare your bid with confidence. Anything marked as "in progress" will be upgraded automatically — no action required from you.
The NHBRC is a regulator established under the Housing Consumers Protection Measures Act, mandated to regulate the home building industry and protect housing consumers. It operates with approximately 544 employees, with head office in Sunninghill, Gauteng, and 9 provincial offices and 12 satellite offices across South Africa.
Important Dates
Source: NHBRC 08 2026 TOR Managed Infrastructure Solution 1.pdf (RFP){"closingDate":"02 OCTOBER 2026","closingTime":"11:00","briefingSession":"{"date":"11 October 2026","time":"11:00","venue":"E: 11 October 2026","is_compulsory":false}"}
Briefing Session
Source: NHBRC 08 2026 TOR Managed Infrastructure Solution 1.pdf (RFP)There will be a non-compulsory hybrid briefing session. The date, time, and venue are not specified in the provided text; refer to the full RFP for details.
Contact Information
Source: NHBRC 08 2026 TOR Managed Infrastructure Solution 1.pdf (RFP){"name":null,"email":null,"phone":null,"department":"Supply Chain Management","address":null}
Evaluation Criteria
Source: NHBRC 08 2026 TOR Managed Infrastructure Solution 1.pdf (RFP)Unable to extract eligibility criteria
Technical Specifications
Source: NHBRC 08 2026 TOR Managed Infrastructure Solution 1.pdf (RFP)4.1. The National Home Builders Registration Council is mandated by the Housing Consumers
Protection Measures Act, 1998 (Act No. ) to regulate the home building industry and
protect housing consumers. The NHBRC ensures that it delivers on its mandate by delivering on
its products and services, and the key performance indicators that are contained in the
organizational scorecard.
Vision
To be the Champion of the Housing Consumers.
Mission
To Protect the Housing Consumers and to Regulate the Homebuilding Environment.
Motto
Assuring Quality Homes.
of 60
Managed Infrastructure Solution
Strategy of nhbrc
The strategy of the NHBRC is based on the following pillars:
industry.
5.1. The purpose of this document is to Request for Proposals (RFP) is to appoint a qualified service provider
to deliver a fully integrated Managed Infrastructure Solution for NHBRC for a period of five (5) years.
5.2. The solution must support NHBRC’s operational, regulatory, and digital transformation requirements
through a secure, scalable, and resilient ICT environment.
5.3. The appointed service provider will assume end-to-end accountability for service delivery, performance,
availability, and continuous improvement across all infrastructure components.
6.1. Current environment
6.1.1. The NHBRC operates a hybrid ICT environment comprising on-premises infrastructure, managed
hosting services, and cloud-based workloads hosted on Microsoft Azure.
6.1.2. The current hosting environment includes:
monthly archive backups, including off-site replication for disaster recovery
purposes
6.1.3. The proposed solution must seamlessly integrate these environments into a unified, secure, and
scalable architecture, ensuring consistency across hosting, identity, backup, and disaster recovery
services.
6.2. Environment sizing and scalability requirements
6.2.1. The solution must be designed based on the current baseline environment and must allow for growth
over the contract period.
6.2.2. Server Spécifications:(Baseline)
Metric Value
Total Servers 19
Total vCPU 106
Total RAM (GB) 860
Total Allocated / Provisioned Storage (GB) 41582,6
Total Allocated / Provisioned Storage (TB) 40,61
Total VMDK In-Use Storage (GB) 41329,7
Servers Powered On 14
Servers Powered Off 5
Storage Tier in Use Silver (100% of allocated capacity)
of 60
Managed Infrastructure Solution
6.3. Scalability expectations
6.3.1. Horizontal and vertical scaling of compute, storage, and network resources
6.3.2. Allow rapid onboarding of new users, offices, applications, and digital services
6.3.3. Increased security and monitoring capacity
6.3.4. Elastic bandwidth and infrastructure scaling
6.3.5. Growth of at least 20% per annum without redesign
7.1. Overview
7.1.1. The NHBRC requires a fully integrated, end-to-end managed infrastructure solution delivered under
a single Service Provider model.
7.1.2. The appointed Service Provider shall be responsible for the design, implementation, integration,
management, and continuous optimisation of all services within scope.
7.1.3. The solution shall cover the following service components:
a) Managed Hosting and Infrastructure (IaaS)
b) Network and Connectivity Services
c) Infrastructure Security and Monitoring
d) Backup, Disaster Recovery and Business Continuity
e) Unified Communications and Collaboration
f) Service Management and Governance
7.1.4. Bidders must propose a single, integrated solution across all service components.
7.1.5. The Service Provider shall act as the prime contractor and shall retain full accountability for all
services, including those delivered through subcontractors, partners, or OEMs.
7.1.6. Where third-party providers are utilised, the Service Provider shall:
Ensure seamless integration across all service components
Remain fully accountable for service delivery, performance, and SLA compliance
Manage all subcontractors and OEMs as part of a unified delivery model
7.1.7. NHBRC shall maintain a single contractual and operational relationship with the appointed Service
Provider.
7.1.8. The Service Provider shall ensure that the solution:
Aligns with NHBRC governance, risk, and compliance requirements
Supports asset ownership and exit management provisions
Provides transparent and cost-effective service delivery
7.1.9. The Service Provider shall be fully accountable for both technical and commercial performance
throughout the contract lifecycle.
of 60
Managed Infrastructure Solution
7.2. Managed hosting and infrastructure-as-a-service (iaas)
7.2.1. The Service Provider shall deliver a secure, scalable, and resilient Infrastructure-as-a-Service (IaaS)
environment aligned to NHBRC’s hybrid ICT operations.
7.2.1.1. The solution shall:
7.2.1.1.1. Support current and future workloads (including SAP and business applications)
7.2.1.1.2. Enable hybrid and cloud-aligned architecture (including Microsoft Azure)
7.2.1.1.3. Ensure high availability and performance across all hosted environments
7.2.2. Data Centre Facilities
7.2.2.1. The Service Provider shall utilise enterprise-grade data centre facilities.
7.2.2.2. The data centre (primary site) must meet the following minimum requirements:
7.2.2.2.1. Tier III certification issued by the Uptime Institute or demonstrate compliance with an
equivalent TIA-942 Rated 3 Facility Certification standard, to ensure high availability,
redundancy, and operational resilience.
7.2.2.2.2. Located within South Africa, with geographic separation between primary and secondary
site.
7.2.2.2.3. Provide environmental monitoring capabilities, including temperature, humidity, fire
detection, and power conditions.
7.2.2.2.4. Include redundant power infrastructure (UPS and backup generators) to ensure continuous
service availability and uninterrupted operations.
7.2.2.2.5. Support secure interconnectivity with major telecommunications providers and cloud
platforms, including Microsoft Azure, Amazon Web Services, and Google Cloud, and must
incorporate appropriate network segmentation measures, including Demilitarized Zones
(DMZs), where applicable.
7.2.2.2.6. Implement robust physical security measures, including 24/7 surveillance, controlled access
mechanisms, and continuous security monitoring.
7.2.2.2.7. Provide an appropriate infrastructure design, including raised flooring where applicable,
structured cabling, and adequate power and cooling capacity to support both current
operational requirements and future scalability needs.
7.2.3. Core Responsibilities
7.2.3.1. The Service Provider shall be responsible for:
7.2.3.1.1. Provision and management of enterprise-grade virtualised infrastructure (compute, storage,
and networking)
7.2.3.1.2. Host and manage NHBRC systems and applications
7.2.3.1.3. Perform workload migration and optimisation
7.2.3.1.4. Manage operating system lifecycle (patching, updates, upgrades)
7.2.3.1.5. Monitoring infrastructure availability, performance, and capacity
7.2.3.1.6. Integration with Microsoft Entra ID (Azure AD) and other IAM services.
7.2.3.1.7. Support for hybrid architecture across on premises, hosted, and cloud environments
of 60
Managed Infrastructure Solution
7.2.4. Architecture and Automation
7.2.4.1. The Service Provider shall implement automated and standardised infrastructure management
practices.
7.2.4.2. This shall include:
7.2.4.2.1. Use of Infrastructure-as-Code (IaC) or equivalent automation tools
7.2.4.2.2. Automated provisioning, configuration, and scaling
7.2.4.2.3. Standardised configuration baselines
7.2.4.2.4. Automated patching and update processes
7.2.4.3. Manual processes must be minimised, and all critical operations must be repeatable, traceable, and
auditable.
7.2.5. Cost Management and Optimisation
7.2.5.1. The Service Provider shall ensure efficient use of infrastructure resources.
7.2.5.2. This includes:
7.2.5.2.1. Monitoring resource consumption
7.2.5.2.2. Rightsizing compute and storage
7.2.5.2.3. Eliminating underutilised resources
7.2.5.2.4. Providing optimisation recommendations
7.2.5.3. The Service Provider shall deliver:
7.2.5.3.1. Monthly utilisation and cost reports
7.2.5.3.2. Recommendations for cost improvements
7.2.6. High Availability and Resilience
7.2.6.1. The solution shall be designed to meet SLA requirements and ensure service continuity.
7.2.6.2. This includes:
7.2.6.2.1. Redundancy across compute, storage, and network layers
7.2.6.2.2. Minimal single points of failure
7.2.6.2.3. Failover and recovery capabilities
7.2.7. Monitoring and Performance Management
7.2.7.1. The Service Provider shall provide continuous monitoring of infrastructure and applications. This
includes:
7.2.7.1.1. 24/7 monitoring of availability and performance
7.2.7.1.2. Proactive alerting on service degradation
7.2.7.1.3. Real-time dashboards aligned to SLA reporting
7.2.7.1.4. Root cause analysis and incident reporting
7.2.8. Asset Ownership and Licensing Model
7.2.8.1. The bidder shall clearly define the ownership model for all components.
of 60
Managed Infrastructure Solution
7.2.8.2. Ownership models may include Service Provider-owned, NHBRC-owned or Hybrid model
7.2.8.3. The proposal must
7.2.8.3.1. Clearly identify ownership of all key components, including compute, storage, networking,
security platforms, software licensing, and management tools.
7.2.8.3.2. Ensure transparency in ownership, access, and control;
7.2.8.3.3. Remain accountable for all assets, regardless of ownership, including insurance.
7.2.8.3.4. Support seamless transition in line with exit management requirements; and
7.2.8.3.5. Avoid dependencies that may restrict NHBRC’s operational or contractual flexibility.
7.2.9. Technology Refresh and Lifecycle Management
7.2.9.1. The Service Provider shall ensure that all technologies utilised in the solution remain vendor-
supported for the duration of the contract.
7.2.9.2. The Service Provider shall:
7.2.9.2.1. Ensure all platforms, systems, and software remain within vendor support lifecycle periods
7.2.9.2.2. Proactively identify and recommend technology refresh or upgrades where required
7.2.9.2.3. Implements refresh activities to maintain performance, security, and supportability of the
environment
7.3. Network, connectivity, and security services
7.3.1. The Service Provider shall design, implement, and manage a secure, reliable, and high-performance
network environment supporting all NHBRC locations and hosted services.
7.3.2. Wide Area Network (WAN) and Branch Connectivity
7.3.2.1. The Service Provider shall provide a resilient Wide Area Network (WAN) solution connecting all
NHBRC sites.
7.3.2.2. The solution must:
7.3.2.2.1. Provide dual connectivity (primary and secondary) links per site
7.3.2.2.2. Ensure high availability
7.3.2.2.3. Support a cloud-aware Software-Defined Wide Area Network (SD-WAN) architecture or
equivalent, capable of intelligent traffic routing and optimisation
7.3.2.2.4. Enable secure connectivity between branch offices, data centres, and cloud environments
(e.g. IPSec or equivalent)
7.3.2.2.5. Provide Quality of Service (QoS) for prioritisation of Microsoft 365, Microsoft Teams voice
and video, SAP and critical business applications
7.3.2.2.6. The proposed solution must align with the existing environment and include a migration
approach where applicable.
7.3.3. Network Performance and Quality
7.3.3.1. The Service Provider shall ensure network performance supports business applications.
7.3.3.2. The solution must support:
7.3.3.2.1. Low latency for real-time services (e.g. voice and video)
7.3.3.2.2. Minimal packet loss and jitter for unified communications
7.3.3.2.3. Consistent bandwidth availability per site
of 60
Managed Infrastructure Solution
7.3.3.3. The Service Provider shall monitor performance and resolve bottlenecks proactively.
7.3.4. LAN and Wireless Infrastructure
7.3.4.1. The Service Provider shall design and manage LAN and wireless infrastructure across all NHBRC
sites.
7.3.4.2. This includes:
7.3.4.2.1. Enterprise-grade switching infrastructure
7.3.4.2.2. VLAN segmentation and access control
7.3.4.2.3. High availability design at core and access layers
7.3.4.2.4. Wireless access with secure authentication
7.3.4.2.5. Segmentation of user groups (corporate, guest, privileged)
7.3.4.2.6. Centralised management and monitoring
7.3.5. Network Security and Integration
7.3.5.1. All network services shall align with the infrastructure security requirements defined in Section 7.4.
7.3.5.2. The solution must Integrate with existing or proposed firewall environments
7.3.5.2.1. Support network segmentation, including DMZ design where required
7.3.5.2.2. Ensure visibility of network traffic
7.3.6. Monitoring and Reporting
7.3.6.1. The Service Provider shall provide end-to-end monitoring of network services. This includes:
7.3.6.1.1. Real-time monitoring of availability, performance, and utilisation
7.3.6.1.2. Proactive alerting and incident notification
7.3.6.1.3. SLA-aligned reporting
7.3.6.1.4. Perform ongoing capacity planning
7.3.7. Data Centre and DR Connectivity
7.3.7.1. The Service Provider shall ensure secure and reliable connectivity between primary and disaster
recovery environments.
7.3.7.2. This includes Support replication traffic and failover operations
7.3.7.2.1. Ensure continuous access during disaster recovery scenarios
7.3.7.2.2. Align with defined DR requirements
7.3.8. Integration Requirements
7.3.8.1. All network services must operate as part of an integrated ICT ecosystem and interoperate
seamlessly with:
7.3.8.1.1. Hosting and infrastructure services
7.3.8.1.2. Security services (Section 7.4)
7.3.8.1.3. Backup and disaster recovery solutions
7.3.8.1.4. Cloud and hybrid environments
of 60
Managed Infrastructure Solution
7.4. Infrastructure security and monitoring
7.4.1. The Service Provider shall implement and manage security controls to protect all infrastructure,
platforms, and environments used to deliver services to the NHBRC.
7.4.1.1. The solution shall ensure the confidentiality, integrity, and availability of the NHBRC systems and
data hosted within the Service Provider’s environment.
7.4.2. Security Responsibility Model
7.4.2.1. The Service Provider shall be responsible for securing and monitoring the infrastructure under its
control.
7.4.2.2. This includes Protection of hosted systems, platforms, and workloads
7.4.2.2.1. Monitoring of infrastructure, network, and platform-level security events
7.4.2.2.2. Detection and response to security threats within the hosting environment
7.4.2.3. The Service Provider shall ensure that all security capabilities integrate with NHBRC’s current or
future security operations, including any centrally managed Security Operations Centre (SOC).
7.4.3. Core Security Controls
7.4.3.1. The Service Provider shall implement and maintain the following:
7.4.3.1.1. Server and infrastructure hardening
7.4.3.1.2. Endpoint Detection and Response (EDR) or equivalent
7.4.3.1.3. Malware protection and threat prevention
7.4.3.1.4. Vulnerability scanning and patch management
7.4.3.1.5. Data encryption (at rest and in transit)
7.4.3.1.6. Network security controls aligned to approved architecture
7.4.3.2. All controls must be aligned with NHBRC security policies and industry best practices.
7.4.4. Minimum Security Control Requirements
7.4.4.1. The Service Provider shall implement and maintain, at a minimum, the following security controls
throughout the contract duration:
7.4.4.1.1. Identity and Access Management
7.4.4.1.2. Multi-Factor Authentication (MFA) for all privileged and remote administrative access.
7.4.4.1.3. Role-Based Access Control (RBAC) aligned to the principle of least privilege.
7.4.4.1.4. Privileged Access Management (PAM) controls for privileged and administrative accounts.
7.4.4.1.5. Periodic access reviews and recertification of privileged accounts.
7.4.4.2. Infrastructure Protection
7.4.4.2.1. Secure configuration baselines aligned to recognised industry standards.
7.4.4.2.2. Endpoint Detection and Response (EDR) and/or Extended Detection and Response (XDR)
capabilities.
7.4.4.2.3. Next-Generation Firewall (NGFW) protection.
7.4.4.2.4. Network segmentation and Zero Trust security principles.
7.4.4.2.5. Web Application Firewall (WAF) protection for internet-facing applications where applicable.
7.4.4.2.6. Distributed Denial of Service (DDoS) protection mechanisms.
7.4.4.3. Vulnerability Management
of 60
Managed Infrastructure Solution
7.4.4.3.1. Quarterly authenticated vulnerability assessments.
7.4.4.3.2. Annual independent penetration testing.
7.4.4.3.3. Risk-based remediation of identified vulnerabilities.
7.4.4.3.4. Patch management aligned with agreed remediation timelines.
7.4.4.4. Data Protection
7.4.4.4.1. Encryption of data at rest and in transit.
7.4.4.4.2. Customer-controlled encryption keys where applicable.
7.4.4.4.3. Secure key management and rotation procedures.
7.4.4.4.4. Data Loss Prevention controls where applicable.
7.4.4.5. Supply Chain Security
7.4.4.5.1. Security due diligence of subcontractors and service partners.
7.4.4.5.2. Continuous monitoring of critical service providers.
7.4.4.5.3. Maintenance of an approved subcontractor register.
7.4.4.6. Assurance
7.4.4.6.1. The Service Provider shall annually provide evidence of independent security assurance
assessments and remediation activities.
7.4.5. Security Monitoring and Event Management
7.4.5.1. The Service Provider shall:
7.4.5.1.1. Monitor systems, networks, and infrastructure for security events
7.4.5.1.2. Generate alerts for suspicious or malicious activity
7.4.5.1.3. Investigate and respond to incidents affecting hosted services
7.4.5.1.4. Timely detection and escalation of security events
7.4.5.1.5. Maintenance of incident logs and audit trails
7.4.5.1.6. Availability of security event data for analysis and reporting
7.4.5.1.7. Provide logs and telemetry to the NHBRC or third-party Security Operations Centre/Security
Information and Event Management (SOC/SIEM) platforms
7.4.5.1.8. Enable integration with centralised monitoring systems
7.4.6. Vulnerability and Patch Management
7.4.6.1. The Service Provider shall implement continuous vulnerability and patch management processes,
including:
7.4.6.1.1. Regular vulnerability scanning across all systems
7.4.6.1.2. Risk-based prioritisation and remediation of identified vulnerabilities
7.4.6.1.3. Timely application of security patches and updates
7.4.6.2. The Service Provider shall provide regular reports on:
7.4.6.2.1. Vulnerability status
7.4.6.2.2. Remediation activities
7.4.6.2.3. Compliance with patching requirements
7.4.7. Incident Management and Response
of 60
Managed Infrastructure Solution
7.4.7.1. The Service Provider shall:
7.4.7.1.1. Detect and respond to security incidents within its environment
7.4.7.1.2. Escalate incidents to the NHBRC in accordance with agreed procedures
7.4.7.1.3. Support investigation, containment, and remediation activities
7.4.7.1.4. Maintain documented incident response procedures
7.4.7.1.5. Provide incident reports, including root cause analysis and corrective actions
7.4.8. Logging and Audit
7.4.8.1. The Service Provider shall implement centralised logging across all managed environments.
7.4.8.2. Logs must:
7.4.8.2.1. Capture system, network, and security events
7.4.8.2.2. Be time-synchronised and protected from tampering
7.4.8.2.3. Be retained in accordance with NHBRC requirements
7.4.8.2.4. Ensure logs are accessible for audit purposes
7.4.8.2.5. Be available for integration into external monitoring platforms
7.4.9. Reporting and Governance
7.4.9.1. The Service Provider should provide regular security reporting, including:
7.4.9.1.1. Security incidents and response actions
7.4.9.1.2. Vulnerability and patch compliance status
7.4.9.1.3. Security risks and trends
7.4.9.2. The Service Provider shall participate in the NHBRC governance structures related to security and
risk management.
7.4.10. Compliance and Standards
7.4.10.1. The Service Provider shall ensure that all security controls and processes align with:
7.4.10.1.1. ISO/IEC 27001:2022 or ISO 22301:2019 or equivalent standards
7.4.10.1.2. POPIA requirements
7.4.10.1.3. NHBRC internal security policies
7.4.11. POPIA Operator Obligations
7.4.11.1. The Service Provider shall act as an Operator as contemplated in the Protection of Personal
Information Act (POPIA).
7.4.11.2. The Service Provider shall:
7.4.11.2.1. Process personal information only on documented instructions from NHBRC.
7.4.11.2.2. Maintain strict confidentiality regarding all NHBRC information.
7.4.11.2.3. Ensure all personnel with access to NHBRC information are appropriately authorised.
7.4.11.2.4. Maintain an approved Sub-Operator Register identifying all subcontractors processing
NHBRC information.
7.4.11.2.5. Obtain prior written approval from NHBRC before appointing any Sub-Operator.
7.4.11.2.6. Ensure all personal information remains hosted within the Republic of South Africa unless
explicitly authorised by NHBRC.
of 60
Managed Infrastructure Solution
7.4.11.2.7. Implement controls governing cross-border transfers of personal information.
7.4.11.2.8. Cooperate fully with NHBRC during security incidents, breach investigations, regulatory
enquiries, and audit activities.
7.4.11.2.9. Notify NHBRC immediately upon becoming aware of an actual or suspected privacy or
security breach.
7.4.11.2.10. Provide NHBRC with audit rights relating to the processing and safeguarding of personal
information.
7.4.11.2.11. Support NHBRC in responding to data-subject requests and regulatory obligations.
7.4.11.2.12. Upon termination or expiry of the contract, return all NHBRC data in an agreed format and
provide certified evidence of secure destruction of residual copies.
7.5. Backup, restore, and business continuity
7.5.1. The Service Provider shall implement and manage a backup and disaster recovery solution to ensure
the protection, availability, and recoverability of NHBRC systems and data.
7.5.2. Recovery Objectives
7.5.2.1. The Service Provider shall define and implement recovery targets aligned to business requirements.
Service Tier RTO RPO
Critical 4 hrs 15 min
Important 8 hrs 1 hr
Standard 24 hrs 24 hrs
7.5.2.2. This includes:
7.5.2.2.1. Defined Recovery Time Objectives (RTO) for system restoration
7.5.2.2.2. Defined Recovery Point Objectives (RPO) for data protection
7.5.3. Backup Services
7.5.3.1. The Service Provider shall:
7.5.3.1.1. Implement backup solutions across all environments
7.5.3.1.2. The backup approach must be daily incremental, full weekly, and a monthly archive
7.5.3.1.3. Perform regular backups of servers, databases, and application data
7.5.3.1.4. Ensure encryption of backup data at rest and in transit
7.5.3.1.5. Backups must:
o Be monitored and verified regularly
o Support restoration at file, system, and application levels
7.5.4. Backup Security and Resilience
7.5.4.1. The backup solution shall incorporate:
7.5.4.1.1. Immutable backup repositories.
7.5.4.1.2. Air-gapped or logically isolated backup copies.
7.5.4.1.3. Backup encryption at rest and in transit.
of 60
Managed Infrastructure Solution
7.5.4.1.4. Backup integrity verification and automated validation processes.
7.5.4.1.5. Regular backup restoration testing.
7.5.4.1.6. Ransomware recovery capabilities.
7.5.4.1.7. Independent administrative credentials for backup environments.
7.5.4.1.8. A 3-2-1-1-0 backup strategy or equivalent.
7.5.4.2. Where 3 copies of data.
7.5.4.2.1. 2 different storage media.
7.5.4.2.2. 1 offsite copy.
7.5.4.2.3. 1 immutable or air-gapped copy.
7.5.4.2.4. 0 backup verification errors.
7.5.5. Disaster Recovery Architecture
7.5.5.1. The Service Provider shall provide a Disaster Recovery environment which:
7.5.5.1.1. Is located within South Africa.
7.5.5.1.2. Is geographically separated from the primary site.
7.5.5.1.3. Utilises separate utility infrastructure and power grids where possible.
7.5.5.1.4. Provides independent network connectivity.
7.5.5.1.5. Maintains sufficient licensed capacity to recover all critical NHBRC workloads.
7.5.5.1.6. Supports encrypted replication between production and DR environments.
7.5.5.1.7. Includes orchestration and automation for recovery activities.
7.5.5.1.8. Provides recovery support for Active Directory, DNS, SAP and critical business systems.
7.5.5.1.9. Includes cyber-recovery capabilities for ransomware and malware events.
7.5.5.1.10. Supports controlled failover and failback procedures.
7.5.5.1.11. Includes periodic data consistency validation.
7.5.5.1.12. Supports annual disaster recovery testing.
7.5.5.2. NHBRC reserves the right to invoke Disaster Recovery during:
7.5.5.2.1. Major service outages.
7.5.5.2.2. Cybersecurity incidents.
7.5.5.2.3. Infrastructure failures.
7.5.5.2.4. Natural disasters.
7.5.5.2.5. Any event materially impacting service availability.
7.5.6. Migration Alignment
7.5.6.1. The establishment of disaster recovery capabilities shall form part of the migration and transition
activities defined in Section 11.
7.5.6.2. The Service Provider shall:
7.5.6.2.1. Define the approach for implementing DR during migration
7.5.6.2.2. Ensure DR capabilities are tested and validated prior to final production cutover
7.5.7. Testing and Validation
of 60
Managed Infrastructure Solution
7.5.7.1. The Service Provider shall perform regular testing of backup and disaster recovery capabilities. This
includes:
7.5.7.1.1. Annual disaster recovery testing
7.5.7.1.2. Periodic backup restoration testing
7.5.7.2. The Service Provider shall:
7.5.7.2.1. Provide documented test results
7.5.7.2.2. Test results shall be submitted to the NHBRC governance structures for review
7.5.7.2.3. Identify and remediate gaps
7.5.8. Monitoring and Reporting
7.5.8.1. The Service Provider shall monitor backup and DR processes
7.5.8.2. Provide regular reports on:
7.5.8.2.1. Backup success/failure reports
7.5.8.2.2. Recovery readiness status
7.5.8.2.3. Storage capacity and retention
7.5.9. Compliance and Integration
7.5.9.1. The backup and disaster recovery solution shall:
7.5.9.1.1. Align with NHBRC policies and regulatory requirements
7.5.9.1.2. Integrate with hosting, network, and security services
7.5.9.2. The Service Provider shall ensure data remains recoverable throughout the contract lifecycle and
supports exit and transition requirements.
7.6. Unified communications and collaboration
7.6.1. The Service Provider shall implement and manage a secure, reliable, and integrated unified
communications solution to support NHBRC’s communication and collaboration needs.
7.6.2. Collaboration Platform
7.6.2.1. The solution shall align to Microsoft 365 and Microsoft Teams. This includes:
7.6.2.1.1. Configure and manage Microsoft Teams for messaging, meetings, and collaboration
7.6.2.1.2. Ensure integration with Exchange Online, SharePoint Online, and OneDrive
7.6.2.1.3. Support collaboration across the organisation
7.6.3. Voice and Telephony Services
7.6.3.1. The Service Provider shall deliver enterprise voice services integrated with Microsoft Teams.
7.6.3.2. This includes:
7.6.3.2.1. Voice enablement (Direct Routing, Operator Connect, or equivalent)
7.6.3.2.2. Inbound and outbound calling
7.6.3.2.3. Number management and porting
7.6.3.2.4. Call routing, queues, and auto-attendants
7.6.3.3. The bidder shall clearly define the proposed voice architecture and dependencies
7.6.3.4. The solution must ensure high availability and service continuity.
of 60
Managed Infrastructure Solution
7.6.4. Performance and User Experience
7.6.4.1. The Service Provider shall ensure consistent and high-quality user experience. This includes:
7.6.4.1.1. Monitoring of call quality and session performance
7.6.4.1.2. Management of latency, jitter, and packet loss
7.6.4.1.3. Alignment with network QoS policies (Section 7.3)
7.6.4.2. The Service Provider shall provide reporting on service quality and usage.
7.6.5. Security and Compliance
7.6.5.1. The unified communications solution shall:
7.6.5.1.1. Integrate with identity and access management controls
7.6.5.1.2. Align with data protection and classification policies
7.6.5.1.3. Support secure access for remote and mobile users
7.6.5.2. Security controls must align with Section 7.4 (Security).
7.6.6. Licensing and Optimisation
7.6.6.1. The Service Provider shall:
7.6.6.1.1. Manage and optimise Microsoft 365 and voice-related licensing
7.6.6.1.2. Ensure efficient allocation of licenses aligned to user needs
7.6.6.1.3. Provide recommendations for cost optimisation
7.6.6.2. The Service Provider shall provide regular reporting on:
7.6.6.2.1. License utilisation
7.6.6.2.2. Usage trends
7.6.6.2.3. Optimisation opportunities
7.6.7. Service Management and Support
7.6.7.1. The Service Provider shall:
7.6.7.1.1. Provide end-user support for communication services
7.6.7.1.2. Manage incidents and service requests
7.6.7.1.3. Maintain service availability in line with SLA requirements
7.6.7.2. Minimum SLA schedule
Priority Acknowledge Response Restore
P1 Critical 15 min 30 min 4 hrs
P2 High 30 min 1 hr 8 hrs
P3 Medium 4 hrs 8 hrs 24 hrs
P4 Low 8 hrs 24 hrs 72 hrs
7.6.7.3. Minimum Availability Requirements
Service Availability
Core Hosting 99.95%
Network Services 99.95%
of 60
Managed Infrastructure Solution
Internet Services 99.90%
Unified Communications 99.90%
Disaster Recovery Platform 99.90%
7.6.7.4. Service metrics:
7.6.7.4.1. Backup success rate ≥ 98%.
7.6.7.4.2. Critical patch deployment ≤ 14 days.
7.6.7.4.3. High-risk vulnerability remediation ≤ 30 days.
7.6.7.4.4. Security event notification ≤ 1 hour of detection.
7.6.7.4.5. Monthly service reports due within 5 business days.
7.6.8. Integration Requirements
7.6.8.1. The Unified Communications solution must integrate with:
7.6.8.1.1. Network and connectivity services (Section 7.3)
7.6.8.1.2. Infrastructure Security and monitoring services (Section 7.4)
7.6.8.1.3. Identity and access management systems
7.7. Service management and governance
7.7.1. The Service Provider shall implement a service management and governance framework to ensure
effective delivery, performance management, and continuous improvement of all services
7.7.2. Service Management Processes
7.7.2.1. The Service Provider shall implement and manage core service management processes, including:
7.7.2.1.1. Incident, problem, and change management
7.7.2.1.2. 24/7/365 service desk support
7.7.2.1.3. Incident escalation and resolution management
7.7.2.1.4. Monthly, quarterly, and annual service performance reports (including availability, security,
and utilisation)
7.7.2.1.5. Participation in NHBRC governance structures, including Change Advisory Board (CAB)
meetings
7.7.2.2. All processes must:
7.7.2.2.1. Be documented and standardised
7.7.2.2.2. Align with recognised best practices (e.g. ITIL)
7.7.2.2.3. Support audit and compliance requirements
7.7.3. Service Level Management
7.7.3.1. The Service Provider shall deliver services in accordance with agreed Service Level Agreements
(SLAs).
7.7.3.2. SLAs shall include measurable targets for:
7.7.3.2.1. Service availability
7.7.3.2.2. Incident response and resolution
7.7.3.2.3. System performance
of 60
Managed Infrastructure Solution
7.7.3.3. The Service Provider shall:
7.7.3.3.1. Monitor SLA performance
7.7.3.3.2. Report on SLA compliance
7.7.3.3.3. Implement corrective actions where required
7.7.3.4. SLA breaches shall be tracked and reported as part of governance reviews
7.7.4. Service Credits
7.7.4.1. Failure to meet SLA targets shall result in service credits.
7.7.4.2. The Service Provider shall:
7.7.4.2.1. Define a clear service credit model
7.7.4.2.2. Apply credits consistently for SLA breaches
7.7.4.2.3. Implement corrective measures for repeated failures
7.7.5. Service Governance Structure
7.7.5.1. The Service Provider shall participate in structured governance forums, including:
7.7.5.1.1. Monthly operational meetings
7.7.5.1.2. Quarterly service review meetings
7.7.5.1.3. Executive-level governance meetings
7.7.5.2. The Service Provider shall provide:
7.7.5.2.1. Service performance reports
7.7.5.2.2. SLA compliance reports
7.7.5.2.3. Incident and problem summaries
7.7.5.2.4. Risk and issue registers
7.7.6. Escalation and Communication
7.7.6.1. The Service Provider shall implement a formal escalation framework.
7.7.6.2. This includes:
7.7.6.2.1. Defined escalation levels (operational, management, executive)
7.7.6.2.2. Clear communication channels
7.7.6.2.3. Timely escalation of critical issues
7.7.7. Continuous Service Improvement
7.7.7.1. The Service Provider shall implement continuous service improvement practices.
7.7.7.2. This includes:
7.7.7.2.1. Identification of improvement opportunities
7.7.7.2.2. Periodic service reviews
7.7.7.2.3. Implementation of agreed improvements
7.7.8. Commercial Benchmarking and Cost Optimisation
7.7.8.1. NHBRC reserves the right to conduct benchmarking reviews during the contract period to ensure
continued value for money.
7.7.8.2. The Service Provider shall:
7.7.8.2.1. Provide required cost and service data
of 60
Managed Infrastructure Solution
7.7.8.2.2. Participate in benchmarking activities
7.7.9. Service Management Tools
7.7.9.1. The Service Provider shall provide tools to support service delivery.
7.7.9.2. This includes:
7.7.9.2.1. Incident and request management systems
7.7.9.2.2. Monitoring and reporting platforms
7.7.9.2.3. Performance tracking tools
7.7.9.3. The tools must provide visibility to NHBRC and support audit requirements.
7.7.10. Resource Model
7.7.10.1. The Service Provider shall:
7.7.10.1.1. Assign dedicated resources per service component
7.7.10.1.2. Maintain appropriately skilled personnel
7.7.10.1.3. Ensure continuity of key resources
7.7.10.1.4. Align resources with the approved organisational structure
8.1. The Service Provider shall develop and implement a structured skills transfer programme covering all
managed services within scope.
8.2. The programme shall include:
o Hosting infrastructure
o Networking and WAN
o Cybersecurity
o Cloud services
o Unified communications
o Disaster recovery
8.3. Progressive knowledge transfer to enable NHBRC operational self-sufficiency over the contract period
8.4. Practical, hands-on training aligned to live environments
8.5. Workshops and awareness sessions aligned to operational needs
9.1 Documentation Requirements during the contract period
9.2 The Service Provider shall develop and maintain up-to-date documentation for all managed services.
a) Solution architecture (logical and physical)
b) Network and system configurations
of 60
Managed Infrastructure Solution
c) Operational procedures and runbooks
d) Security configurations and standards
e) Roles, responsibilities, and organisational structure
f) Service management processes
9.3. Documentation Management All documentation shall be:
9.3.1.1.1. Be maintained and kept current throughout the contract period
9.3.1.1.2. Be updated following changes, upgrades, or material incidents
9.3.1.1.3. Be stored in a format accessible to NHBRC
9.4. Documentation shall be provided to NHBRC upon request or during governance reviews
10.1The Service Provider shall provide 24x7x365 technical support across the full ICT environment, including:
a) Incident management, escalation, and resolution
b) Infrastructure support across hosting, network, security, cloud, and UC services
c) Support for upgrades, refreshes, and infrastructure changes
10.2. Assistance with NHBRC ICT projects and initiatives
10.3. Participation in operational and governance forums where required
11.1. The Service Provider shall plan and execute an end-to-end migration from the current NHBRC
environment to the proposed solution.
11.1.1. The migration shall include all service domains:
10.3.1.1.1. Migration of existing production systems and services
10.3.1.1.2. Implementation of new components required for the target environment, including
disaster recovery capabilities
11.2. Migration Approach
11.2.1. The migration shall be executed in structured phases, including:
a) Assessment and discovery of the current environment
b) Migration planning and cutover strategy
c) Pilot migration and validation
d) Full production migration
e) Post-migration stabilisation and support
11.2.2. The migration timeline shall be proposed by the bidder and approved by NHBRC.
11.3. Migration Requirements
11.3.1. The Service Provider shall provide:
of 60
Managed Infrastructure Solution
11.3.1.1.1. Incumbent provider handover.
11.3.1.1.2. Environment discovery and assessment.
11.3.1.1.3. Application dependency mapping.
11.3.1.1.4. Licensing transfer activities.
11.3.1.1.5. Security and penetration testing.
11.3.1.1.6. Data validation and reconciliation.
11.3.1.1.7. Number porting for telephony services.
11.3.1.1.8. Pilot migration activities.
11.3.1.1.9. Parallel-run period where applicable.
11.3.1.1.10. Change freeze management.
11.3.1.1.11. Rollback procedures.
11.3.1.1.12. Business continuity arrangements.
11.3.1.1.13. Hypercare support following go-live.
11.3.1.1.14. Legacy environment decommissioning.
11.3.2. Acceptance Criteria
11.3.3. Migration shall only be deemed complete after:
11.3.3.1.1. Successful testing.
11.3.3.1.2. User acceptance.
11.3.3.1.3. Documentation handover.
11.3.3.1.4. Knowledge transfer completion.
11.3.3.1.5. Formal NHBRC sign-off.
11.4. Transition Requirements
11.4.1. The Service Provider shall ensure:
a) Minimal downtime during migration activities
b) Controlled and approved cutover processes
c) Implementation of rollback strategies for critical systems
d) Validation of services prior to final cutover
e) No disruption to critical business services during business hours, unless approved by
Nhbrc
11.5. Testing and Acceptance
11.5.1. The Service Provider shall:
a) Perform pre-cutover testing of all services
b) Validate performance, security, and connectivity in the new environment
c) Obtain NHBRC sign-off prior to final production cutover
11.6. Handover and Close-Out
11.6.1. Upon completion of migration, the Service Provider shall:
a) Provide as-built documentation of the migrated environment
b) Deliver updated architecture, configuration, and operational documentation
of 60
Managed Infrastructure Solution
c) Conduct formal handover to NHBRC ICT teams
d) Complete knowledge transfer activities and obtain sign-off
12.1. The Service Provider shall deliver the following:
12.1.1. A detailed implementation plan including phases, milestones, dependencies, resources,
and timelines for all managed services.
12.2. Implementation and Migration
12.2.1. Detailed implementation plan (phases, milestones, dependencies, timelines)
12.2.2. Migration and transition plan including:
a) Hosting infrastructure
b) Network and connectivity
c) Unified communications
d) Disaster recovery implementation
e) Rollback and recovery strategy
12.3. Solution Design Documentation
a) Logical and physical architecture
b) Security architecture
c) Integration architecture across all services
d) Network and connectivity diagrams
12.4. Backup and Disaster Recovery
12.4.1. Disaster recovery plan, including architecture and procedures
12.4.2. DR test reports and remediation actions
12.4.3. Backup strategy, including:
a) Policies and schedules
b) Retention rules
c) Restoration procedures
d) Evidence of restore testing
12.5. Service Reporting
12.5.1. Monthly reports including:
a) SLA performance and availability
b) Capacity and utilisation
c) Security posture summary
d) Incident and root cause analysis
12.6. Knowledge Transfer
12.6.1. Skills transfer plan
12.6.2. Training materials and documentation
of 60
Managed Infrastructure Solution
12.6.3. Operational runbooks and procedures
12.6.4. Formal handover to NHBRC
12.7. Exit and Transition Management
12.7.1. The Service Provider shall develop and maintain a detailed Exit Management Plan.
12.7.2. The plan shall include:
12.7.2.1. Data handover procedures.
12.7.2.2. Configuration exports.
12.7.2.3. Administrative credential transfer.
12.7.2.4. Asset transfer requirements.
12.7.2.5. Licensing transfer arrangements.
12.7.2.6. Knowledge transfer activities.
12.7.2.7. Documentation handover.
12.7.2.8. Successor-provider support.
12.7.2.9. Service transition staffing.
12.7.2.10. Secure destruction procedures.
12.7.2.11. Decommissioning activities.
12.7.3. No vendor lock-in mechanisms shall be permitted.
12.8. Exit and Transition Support
12.8.1. The Service Provider shall provide exit support upon contract expiry or termination.
12.8.2. The exit period shall:
a) Be a minimum of three (3) months and up to six (6) months
b) Form part of the contract terms
12.8.3. During this period, the Service Provider shall:
a) Ensure uninterrupted service delivery
b) Provide full cooperation with NHBRC and any successor provider
c) Transfer all services and operational responsibilities
12.8.4. The Service Provider shall provide:
a) Complete and up-to-date documentation
b) Administrative access and system credentials
c) Knowledge transfer sessions
12.8.5. The Service Provider shall:
a) Continue to meet SLA requirements
b) Not degrade service levels
12.8.6. No additional exit fees shall be charged, except where pre-approved by NHBRC.
12.8.7. Failure to comply shall constitute a material breach of contract.
12.9. Exit Management Deliverables
12.9.1. The Service Provider shall:
of 60
Managed Infrastructure Solution
12.9.1.1.1. Deliver the initial Exit Management Plan within 30 calendar days of
contract commencement.
12.9.1.1.2. Review and update the Exit Plan annually.
12.9.1.1.3. Conduct an executable exit readiness test during the final year of the
contract.
12.9.1.1.4. Maintain ownership records for all assets, documentation, automation
scripts, credentials, and configurations.
12.9.1.1.5. Provide secure deletion certificates upon completion of transition.
13.1. The contract shall include:
13.1.1.1.1. Annual performance reviews.
13.1.1.1.2. Annual value-for-money reviews.
13.1.1.1.3. Benchmarking reviews.
13.1.1.1.4. Audit rights.
13.1.1.1.5. Change-control governance processes.
13.1.1.1.6. Termination for material breach.
13.1.1.1.7. Termination for repeated SLA failures.
13.1.1.1.8. Termination for insolvency.
13.1.1.1.9. Termination for serious security breaches.
13.1.1.1.10. Termination for convenience subject to contractual notice periods.
13.2. The five-year term shall commence upon signing of contract.
13.3. The contract shall include an initial implementation and migration phase, during which the Service
Provider shall achieve service stability and operational readiness prior to full-service commencement,
as defined in Section 11 (Migration Requirements).
13.4. Any extension or renewal of the contract shall be subject to:
a) NHBRC approval
b) Performance against agreed SLAs
13.4.1.1.1. Budget availability and procurement governance requirements
13.5. Upon expiry or termination of the contract, the Service Provider shall comply with the exit and
transition requirements defined in Section 12 (Deliverables).
13.6. The contract shall be governed by provisions relating to:
a) Asset ownership
b) Exit and transition obligations
c) Commercial benchmarking
13.7. These provisions shall remain binding for the full duration of the contract, including any
extensions.
of 60
Managed Infrastructure Solution
14.1. The NHBRC standard working hours are 08:30 to 16:30, Monday to Friday. The Service Provider
shall ensure resource availability and service coverage within these hours.
14.2. The Service Provider shall ensure resources are available for support, escalation, and
operational requirements as reasonably required by NHBRC, including after-hours support for
critical incidents.
14.3. The Service Provider shall deploy suitably skilled resources either:
14.3.1. On-site at NHBRC premises, or
14.3.2. Remotely in accordance with NHBRC policies and operational requirements.
14.4. Resource deployment shall ensure continuity of services and achievement of agreed SLAs.
14.5. The Service Provider shall ensure that all service delivery models, including asset ownership
structures and transition arrangements, support long-term operational sustainability and avoid
vendor lock-in.
14.6. The Service Provider shall execute all assigned tasks and deliverables within agreed timeframes
and in accordance with approved service management processes.
14.7. The Service Provider shall propose and implement cost-effective service delivery models that
optimise performance, efficiency, and value for money, while meeting NHBRC operational
requirements.
14.8. All queries, requests, and operational communications from NHBRC shall be acknowledged as
per the priority matrix, with resolution timelines governed by the applicable SLA classification.
15.1. The Service Provider shall implement end-to-end monitoring across all managed services, including
hosting, network, WAN, internet, unified communications, and disaster recovery environments to
ensure continuous visibility of availability, performance, security, and data integrity.
15.2. The Service Provider shall provide monthly service reports covering, at a minimum:
15.2.1. SLA performance and compliance
15.2.2. System uptime and availability
15.2.3. Capacity and utilisation trends
15.2.4. Security incidents and posture summary
15.2.5. All incidents, outages, and service interruptions
15.3. The Service Provider shall maintain real-time monitoring, alerting, and incident logging capabilities to
enable proactive detection, escalation, and resolution of service issues.
15.4. At contract termination or expiry, the Service Provider shall submit a comprehensive end-of-contract
report detailing:
15.4.1. Overall service performance against SLAs
of 60
Managed Infrastructure Solution
15.4.2. Major incidents and recurring risks
15.4.3. Capacity and infrastructure utilisation trends
15.4.4. Security posture and key vulnerabilities
15.4.5. Recommendations for service optimisation and continuous improvement
16.1. General requirements
16.1.1. The NHBRC requires submissions from competent and experienced organisations with
proven capability in Managed Hosting Infrastructure Services, Unified Communications,
and Business Continuity and Disaster Recovery.
16.1.2. Bidders shall provide verifiable evidence of relevant experience and technical capability.
16.2. Requisites of the service provider
16.2.1. Bidders must submit a comprehensive proposal including the following:
16.2.2. A clear articulation of the bidder’s understanding of the Terms of Reference and scope of
services.
16.2.3. Details of the proposed project team, including:
a) Roles and responsibilities
b) CVs of key personnel
c) Certified copies of qualifications (not older than 6 months)
d) Relevant certifications and experience
16.2.4. Description of the bidder’s quality assurance methodology, including:
a) Service delivery controls
b) Governance processes
c) Risk and issue management approach
16.2.5. A detailed Pricing Schedule must be submitted in accordance with Annexure C to
Annexure H.
16.3. Summary of projects executed and completed
16.3.1. The bidder must demonstrate proven experience in delivering similar projects within the
last five (5) years.
of 60
Managed Infrastructure Solution
16.3.2. The following information must be submitted:
Name of Project Contract Contract Client Name Client
Project Description Value (incl. Duration Contact Tel
VAT)
16.3.3. Each listed project above must be supported by:
16.3.3.1.1. Signed client reference letter on official letterhead
16.3.3.1.2. Confirmation of successful project completion
16.3.3.1.3. Contactable client reference
16.3.3.1.4. Project value
16.4. Key personnel requirements
16.4.1. Bidders must assign suitably qualified and experienced personnel to the project.
16.4.2. A summary of key personnel must be provided in the following format:
No. Full Name Role Qualifications Specialisation Years of
Methodology
Source: NHBRC 08 2026 TOR Managed Infrastructure Solution 1.pdf (RFP)The scope of work requires a fully integrated, end-to-end managed infrastructure solution delivered under a single Service Provider model. The Service Provider shall be responsible for design, implementation, integration, management, and continuous optimisation of all services. Service components include: Managed Hosting and Infrastructure (IaaS), Network and Connectivity Services, Infrastructure Security and Monitoring, Backup, Disaster Recovery and Business Continuity, Unified Communications and Collaboration, and Service Management and Governance. The Service Provider shall act as prime contractor and retain full accountability for all services, including those delivered through subcontractors, partners, or OEMs.
Experience & Qualifications
Source: NHBRC 08 2026 TOR Managed Infrastructure Solution 1.pdf*Please attach recently (last 6 months) certified copies of academic qualifications.
Note: in addition, please provide the following:
16.4.3. CV for each of the project team members highlighting specific and relevant qualifications
and experience.
16.4.4. Key personnel may only be replaced by personnel with similar expertise over the life of the
contract and written permission must be obtained from the NHBRC.
16.4.5. Provide project details of projects that were successfully completed in the last five (5) years
in the format above. For each of these projects, a reference letter of successful completion
of the project must be provided by the client, on the client’s letterhead, and signed off
by an authorised delegated employee of the client.
of 60
Managed Infrastructure Solution
7.6.4. Performance and User Experience
7.6.4.1. The Service Provider shall ensure consistent and high-quality user experience. This includes:
7.6.4.1.1. Monitoring of call quality and session performance
7.6.4.1.2. Management of latency, jitter, and packet loss
7.6.4.1.3. Alignment with network QoS policies (Section 7.3)
7.6.4.2. The Service Provider shall provide reporting on service quality and usage.
7.6.5. Security and Compliance
7.6.5.1. The unified communications solution shall:
7.6.5.1.1. Integrate with identity and access management controls
7.6.5.1.2. Align with data protection and classification policies
7.6.5.1.3. Support secure access for remote and mobile users
7.6.5.2. Security controls must align with Section 7.4 (Security).
7.6.6. Licensing and Optimisation
7.6.6.1. The Service Provider shall:
7.6.6.1.1. Manage and optimise Microsoft 365 and voice-related licensing
7.6.6.1.2. Ensure efficient allocation of licenses aligned to user needs
7.6.6.1.3. Provide recommendations for cost optimisation
7.6.6.2. The Service Provider shall provide regular reporting on:
7.6.6.2.1. License utilisation
7.6.6.2.2. Usage trends
7.6.6.2.3. Optimisation opportunities
7.6.7. Service Management and Support
7.6.7.1. The Service Provider shall:
7.6.7.1.1. Provide end-user support for communication services
7.6.7.1.2. Manage incidents and service requests
7.6.7.1.3. Maintain service availability in line with SLA requirements
7.6.7.2. Minimum SLA schedule
16.1. General requirements
16.1.1. The NHBRC requires submissions from competent and experienced organisations with
proven capability in Managed Hosting Infrastructure Services, Unified Communications,
and Business Continuity and Disaster Recovery.
16.1.2. Bidders shall provide verifiable evidence of relevant experience and technical capability.
16.2. Requisites of the service provider
16.2.1. Bidders must submit a comprehensive proposal including the following:
16.2.2. A clear articulation of the bidder’s understanding of the Terms of Reference and scope of
services.
16.2.3. Details of the proposed project team, including:
a) Roles and responsibilities
b) CVs of key personnel
c) Certified copies of qualifications (not older than 6 months)
d) Relevant certifications and experience
16.2.4. Description of the bidder’s quality assurance methodology, including:
a) Service delivery controls
b) Governance processes
c) Risk and issue management approach
16.2.5. A detailed Pricing Schedule must be submitted in accordance with Annexure C to
16.3. Summary of projects executed and completed
16.3.1. The bidder must demonstrate proven experience in delivering similar projects within the
last five (5) years.
of 60
Project Description Value (incl. Duration Contact Tel
VAT)
16.3.3. Each listed project above must be supported by:
16.3.3.1.1. Signed client reference letter on official letterhead
16.3.3.1.2. Confirmation of successful project completion
16.3.3.1.3. Contactable client reference
16.3.3.1.4. Project value
16.4. Key personnel requirements
16.4.1. Bidders must assign suitably qualified and experienced personnel to the project.
16.4.2. A summary of key personnel must be provided in the following format:
Experience
*Please attach recently (last 6 months) certified copies of academic qualifications.
Note: in addition, please provide the following:
16.4.3. CV for each of the project team members highlighting specific and relevant qualifications
and experience.
16.4.4. Key personnel may only be replaced by personnel with similar expertise over the life of the
contract and written permission must be obtained from the NHBRC.
16.4.5. Provide project details of projects that were successfully completed in the last five (5) years
in the format above. For each of these projects, a reference letter of successful completion
of the project must be provided by the client, on the client’s letterhead, and signed off
by an authorised delegated employee of the client.
of 60
Compliance Requirements
Source: NHBRC 08 2026 TOR Managed Infrastructure Solution 1.pdf (RFP)Central Supplier Database (“the CSD”) and ensure
a) The Bidder must be registered on the National Treasury’s Central Supplier Database (“the CSD”) and ensure
that, if it is successful, it remains so registered and further ensure that the information on the CSD is up-to-date
provide the NHBRC with a Tax Clearance Certificate issued by the South African Revenue Services (“SARS”) on
b) CVs of key personnel
c) Certified copies of qualifications (not older than 6 months)
16.2.5. A detailed Pricing Schedule must be submitted in accordance with Annexure C to
16.4. Key personnel requirements
16.4.2. A summary of key personnel must be provided in the following format
No. Full Name Role Qualifications Specialisation Years of
*Please attach recently (last 6 months) certified copies of academic qualifications.
Note: in addition, please provide the following
16.4.3. CV for each of the project team members highlighting specific and relevant qualifications
16.4.4. Key personnel may only be replaced by personnel with similar expertise over the life of the
Contractual Terms
Source: NHBRC 08 2026 TOR Managed Infrastructure Solution 1.pdf1.1. This Request for Proposal (RFP) has been compiled by the NHBRC, and it is made available to the Bidders on
the following basis.
1.2. Bidders submitting a Bid in response to this RFP are deemed to do so on the basis that they acknowledge and
accept the terms and conditions set out below:
a) The Bidder must be registered on the National Treasury’s Central Supplier Database (“the CSD”) and ensure
that, if it is successful, it remains so registered and further ensure that the information on the CSD is up-to-date
for the duration of the contract.
b) The Bidder must ensure that it is tax compliant at the time of submitting its bid in response to this RFP, and if it is
successful, it remains tax compliant for the duration of the contract. In this regard, the Bidder undertakes to
provide the NHBRC with a Tax Clearance Certificate issued by the South African Revenue Services (“SARS”) on
an annual basis, confirming that it is tax compliant.
c) The NHBRC reserves the right to amend, modify or withdraw this RFP or amend, modify or terminate any of the
procedures or requirements set out herein at any time (and from time to time), without prior notice and without
liability to compensate or reimburse any person.
d) If the NHBRC amends this RFP, the amendment will be sent to each Bidder in writing or publicized as the case
may be. No oral amendments by any person will be considered or acknowledged.
e) The NHBRC reserves the right to carry out site inspections or call for supporting documentation in order to confirm
any information provided by a Bidder in its RFP Bid.
f) This RFP is not intended to form the basis of a decision to enter into any transaction involving the NHBRC and
does not constitute an offer or recommendation to enter into such transaction, or an intention to enter into any
legal relationship with any person.
g) A Bid submitted in response to this RFP will constitute a binding offer which will remain binding and irrevocable
for a period of ninety (90) days from the date of submission to the NHBRC. The offer constituted by the Bid will
be deemed not to have been accepted and no agreement will be deemed to be reached with any Bidder, unless
and until a binding Agreement and other related transactions/documents are concluded between the NHBRC and
the Preferred Bidder.
h) The distribution of this RFP outside the Republic of South Africa may be restricted or prohibited by the laws of
other countries. Recipients of this RFP are advised to familiarize themselves with and comply with all such
restrictions or prohibitions applicable in those jurisdictions, and neither the NHBRC nor any of their respective
directors, officers, employees, agents, representatives or advisors, accepts liability to any person for any damages
arising out of or in connection with the breach of any restriction or provision outside the Republic of South Africa.
2.1. The National Home Builders Registration Council (NHBRC) is a regulator established in terms of
section 2 of the Housing Consumers Protection Measures Act (“the Act”). Section 3 of
the Act provides that the objects of the NHBRC are to:
homes;
regulate the home building industry;
provide protection to housing consumers in respect of the failure of home builders to comply with their
obligations in terms of this Act;
establish and promote ethical and technical standards in the home building industry;
improve structural quality in the interests of housing consumers and the home-building industry;
promote housing consumer rights and to provide housing consumer information;
communicate with and to assist home builders to register in terms of this Act;
assist home builders, through training and inspection, to achieve and maintain satisfactory technical
standards of home building;
regulate insurers contemplated in section 23 (9) (a); and
in particular, achieve the stated objectives of this section in the subsidy housing sector.
“to engage in undertakings to promote improved structural quality of homes constructed in the
Republic;
Act.”
a) The NHBRC's primary mandate is to manage the risk of structural defects in the home building
industry and in so doing, protect the consumer. A prime activity of the NHBRC is to manage its risk
exposure in terms of the warranty scheme, in order to ensure that it is not unduly exposed to claims.
and construction rules, and the appointment of competent persons by the Home Builder to perform
certain tasks.
b) The NHBRC’s goal is to ensure capital preservation to ensure it remains financially viable to meet
claims as they arise and that no recourse to the Minister of Human Settlements for additional funds
is necessary at any time in terms of section 17(3)-(5) of the Act.
c) The annual actuarial report is required in terms of the Housing Consumers Protection Measures
Act, to value the actuarial liabilities of the NHBRC’s warranty fund.
d) The investment strategy should be implemented with due regard to the liabilities of the NHBRC, the
nature of the funds in general, Solvency Assessment and Management (SAM) and the low-risk
tolerance and return requirements of the Council.
industry.
5.1. The purpose of this document is to Request for Proposals (RFP) is to appoint a qualified service provider
to deliver a fully integrated Managed Infrastructure Solution for NHBRC for a period of five (5) years.
5.2. The solution must support NHBRC’s operational, regulatory, and digital transformation requirements
through a secure, scalable, and resilient ICT environment.
5.3. The appointed service provider will assume end-to-end accountability for service delivery, performance,
availability, and continuous improvement across all infrastructure components.
7.2.8.2. Ownership models may include Service Provider-owned, NHBRC-owned or Hybrid model
7.2.8.3. The proposal must
7.2.8.3.1. Clearly identify ownership of all key components, including compute, storage, networking,
security platforms, software licensing, and management tools.
7.2.8.3.2. Ensure transparency in ownership, access, and control;
7.2.8.3.3. Remain accountable for all assets, regardless of ownership, including insurance.
7.2.8.3.4. Support seamless transition in line with exit management requirements; and
7.2.8.3.5. Avoid dependencies that may restrict NHBRC’s operational or contractual flexibility.
7.2.9. Technology Refresh and Lifecycle Management
7.2.9.1. The Service Provider shall ensure that all technologies utilised in the solution remain vendor-
supported for the duration of the contract.
7.2.9.2. The Service Provider shall:
7.2.9.2.1. Ensure all platforms, systems, and software remain within vendor support lifecycle periods
7.2.9.2.2. Proactively identify and recommend technology refresh or upgrades where required
7.2.9.2.3. Implements refresh activities to maintain performance, security, and supportability of the
environment
7.3. Network, connectivity, and security services
7.3.1. The Service Provider shall design, implement, and manage a secure, reliable, and high-performance
network environment supporting all NHBRC locations and hosted services.
7.3.2. Wide Area Network (WAN) and Branch Connectivity
7.3.2.1. The Service Provider shall provide a resilient Wide Area Network (WAN) solution connecting all
7.4. Infrastructure security and monitoring
7.4.1. The Service Provider shall implement and manage security controls to protect all infrastructure,
platforms, and environments used to deliver services to the NHBRC.
7.4.1.1. The solution shall ensure the confidentiality, integrity, and availability of the NHBRC systems and
data hosted within the Service Provider’s environment.
7.4.2. Security Responsibility Model
7.4.2.1. The Service Provider shall be responsible for securing and monitoring the infrastructure under its
control.
7.4.2.2. This includes Protection of hosted systems, platforms, and workloads
7.4.2.2.1. Monitoring of infrastructure, network, and platform-level security events
7.4.2.2.2. Detection and response to security threats within the hosting environment
7.4.2.3. The Service Provider shall ensure that all security capabilities integrate with NHBRC’s current or
future security operations, including any centrally managed Security Operations Centre (SOC).
7.4.3. Core Security Controls
7.4.3.1. The Service Provider shall implement and maintain the following:
7.4.3.1.1. Server and infrastructure hardening
7.4.3.1.2. Endpoint Detection and Response (EDR) or equivalent
7.4.3.1.3. Malware protection and threat prevention
7.4.3.1.4. Vulnerability scanning and patch management
7.4.3.1.5. Data encryption (at rest and in transit)
7.4.3.1.6. Network security controls aligned to approved architecture
7.4.3.2. All controls must be aligned with NHBRC security policies and industry best practices.
7.4.4. Minimum Security Control Requirements
7.4.4.1. The Service Provider shall implement and maintain, at a minimum, the following security controls
throughout the contract duration:
7.4.4.1.1. Identity and Access Management
7.4.4.1.2. Multi-Factor Authentication (MFA) for all privileged and remote administrative access.
7.4.4.1.3. Role-Based Access Control (RBAC) aligned to the principle of least privilege.
7.4.4.1.4. Privileged Access Management (PAM) controls for privileged and administrative accounts.
7.4.4.1.5. Periodic access reviews and recertification of privileged accounts.
7.4.4.2. Infrastructure Protection
7.4.4.2.1. Secure configuration baselines aligned to recognised industry standards.
7.4.4.2.2. Endpoint Detection and Response (EDR) and/or Extended Detection and Response (XDR)
capabilities.
7.4.4.2.3. Next-Generation Firewall (NGFW) protection.
7.4.4.2.4. Network segmentation and Zero Trust security principles.
7.4.4.2.5. Web Application Firewall (WAF) protection for internet-facing applications where applicable.
7.4.4.2.6. Distributed Denial of Service (DDoS) protection mechanisms.
7.4.4.3. Vulnerability Management
of 60
7.4.7.1. The Service Provider shall:
7.4.7.1.1. Detect and respond to security incidents within its environment
7.4.7.1.2. Escalate incidents to the NHBRC in accordance with agreed procedures
7.4.7.1.3. Support investigation, containment, and remediation activities
7.4.7.1.4. Maintain documented incident response procedures
7.4.7.1.5. Provide incident reports, including root cause analysis and corrective actions
7.4.8. Logging and Audit
7.4.8.1. The Service Provider shall implement centralised logging across all managed environments.
7.4.8.2. Logs must:
7.4.8.2.1. Capture system, network, and security events
7.4.8.2.2. Be time-synchronised and protected from tampering
7.4.8.2.3. Be retained in accordance with NHBRC requirements
7.4.8.2.4. Ensure logs are accessible for audit purposes
7.4.8.2.5. Be available for integration into external monitoring platforms
7.4.9. Reporting and Governance
7.4.9.1. The Service Provider should provide regular security reporting, including:
7.4.9.1.1. Security incidents and response actions
7.4.9.1.2. Vulnerability and patch compliance status
7.4.9.1.3. Security risks and trends
7.4.9.2. The Service Provider shall participate in the NHBRC governance structures related to security and
risk management.
7.4.10. Compliance and Standards
7.4.10.1. The Service Provider shall ensure that all security controls and processes align with:
7.4.10.1.1. ISO/IEC 27001:2022 or ISO 22301:2019 or equivalent standards
7.4.10.1.2. POPIA requirements
7.4.10.1.3. NHBRC internal security policies
7.4.11. POPIA Operator Obligations
7.4.11.1. The Service Provider shall act as an Operator as contemplated in the Protection of Personal
Information Act (POPIA).
7.4.11.2. The Service Provider shall:
7.4.11.2.1. Process personal information only on documented instructions from NHBRC.
7.4.11.2.2. Maintain strict confidentiality regarding all NHBRC information.
7.4.11.2.3. Ensure all personnel with access to NHBRC information are appropriately authorised.
7.4.11.2.4. Maintain an approved Sub-Operator Register identifying all subcontractors processing
7.4.11.2.7. Implement controls governing cross-border transfers of personal information.
7.4.11.2.8. Cooperate fully with NHBRC during security incidents, breach investigations, regulatory
enquiries, and audit activities.
7.4.11.2.9. Notify NHBRC immediately upon becoming aware of an actual or suspected privacy or
security breach.
7.4.11.2.10. Provide NHBRC with audit rights relating to the processing and safeguarding of personal
information.
7.4.11.2.11. Support NHBRC in responding to data-subject requests and regulatory obligations.
7.4.11.2.12. Upon termination or expiry of the contract, return all NHBRC data in an agreed format and
provide certified evidence of secure destruction of residual copies.
7.5. Backup, restore, and business continuity
7.5.1. The Service Provider shall implement and manage a backup and disaster recovery solution to ensure
the protection, availability, and recoverability of NHBRC systems and data.
7.5.2. Recovery Objectives
7.5.2.1. The Service Provider shall define and implement recovery targets aligned to business requirements.
7.7.3.3. The Service Provider shall:
7.7.3.3.1. Monitor SLA performance
7.7.3.3.2. Report on SLA compliance
7.7.3.3.3. Implement corrective actions where required
7.7.3.4. SLA breaches shall be tracked and reported as part of governance reviews
7.7.4. Service Credits
7.7.4.1. Failure to meet SLA targets shall result in service credits.
7.7.4.2. The Service Provider shall:
7.7.4.2.1. Define a clear service credit model
7.7.4.2.2. Apply credits consistently for SLA breaches
7.7.4.2.3. Implement corrective measures for repeated failures
7.7.5. Service Governance Structure
7.7.5.1. The Service Provider shall participate in structured governance forums, including:
7.7.5.1.1. Monthly operational meetings
7.7.5.1.2. Quarterly service review meetings
7.7.5.1.3. Executive-level governance meetings
7.7.5.2. The Service Provider shall provide:
7.7.5.2.1. Service performance reports
7.7.5.2.2. SLA compliance reports
7.7.5.2.3. Incident and problem summaries
7.7.5.2.4. Risk and issue registers
7.7.6. Escalation and Communication
7.7.6.1. The Service Provider shall implement a formal escalation framework.
7.7.6.2. This includes:
7.7.6.2.1. Defined escalation levels (operational, management, executive)
7.7.6.2.2. Clear communication channels
7.7.6.2.3. Timely escalation of critical issues
7.7.7. Continuous Service Improvement
7.7.7.1. The Service Provider shall implement continuous service improvement practices.
7.7.7.2. This includes:
7.7.7.2.1. Identification of improvement opportunities
7.7.7.2.2. Periodic service reviews
7.7.7.2.3. Implementation of agreed improvements
7.7.8. Commercial Benchmarking and Cost Optimisation
7.7.8.1. NHBRC reserves the right to conduct benchmarking reviews during the contract period to ensure
continued value for money.
7.7.8.2. The Service Provider shall:
7.7.8.2.1. Provide required cost and service data
of 60
12.6.3. Operational runbooks and procedures
12.6.4. Formal handover to NHBRC
12.7. Exit and Transition Management
12.7.1. The Service Provider shall develop and maintain a detailed Exit Management Plan.
12.7.2. The plan shall include:
12.7.2.1. Data handover procedures.
12.7.2.2. Configuration exports.
12.7.2.3. Administrative credential transfer.
12.7.2.4. Asset transfer requirements.
12.7.2.5. Licensing transfer arrangements.
12.7.2.6. Knowledge transfer activities.
12.7.2.7. Documentation handover.
12.7.2.8. Successor-provider support.
12.7.2.9. Service transition staffing.
12.7.2.10. Secure destruction procedures.
12.7.2.11. Decommissioning activities.
12.7.3. No vendor lock-in mechanisms shall be permitted.
12.8. Exit and Transition Support
12.8.1. The Service Provider shall provide exit support upon contract expiry or termination.
12.8.2. The exit period shall:
a) Be a minimum of three (3) months and up to six (6) months
b) Form part of the contract terms
12.8.3. During this period, the Service Provider shall:
a) Ensure uninterrupted service delivery
b) Provide full cooperation with NHBRC and any successor provider
c) Transfer all services and operational responsibilities
12.8.4. The Service Provider shall provide:
a) Complete and up-to-date documentation
b) Administrative access and system credentials
c) Knowledge transfer sessions
12.8.5. The Service Provider shall:
a) Continue to meet SLA requirements
b) Not degrade service levels
12.8.6. No additional exit fees shall be charged, except where pre-approved by NHBRC.
12.8.7. Failure to comply shall constitute a material breach of contract.
12.9. Exit Management Deliverables
12.9.1. The Service Provider shall:
of 60
13.1. The contract shall include:
13.1.1.1.1. Annual performance reviews.
13.1.1.1.2. Annual value-for-money reviews.
13.1.1.1.3. Benchmarking reviews.
13.1.1.1.4. Audit rights.
13.1.1.1.5. Change-control governance processes.
13.1.1.1.6. Termination for material breach.
13.1.1.1.7. Termination for repeated SLA failures.
13.1.1.1.8. Termination for insolvency.
13.1.1.1.9. Termination for serious security breaches.
13.1.1.1.10. Termination for convenience subject to contractual notice periods.
13.2. The five-year term shall commence upon signing of contract.
13.3. The contract shall include an initial implementation and migration phase, during which the Service
as defined in Section 11 (Migration Requirements).
13.4. Any extension or renewal of the contract shall be subject to:
a) NHBRC approval
b) Performance against agreed SLAs
13.4.1.1.1. Budget availability and procurement governance requirements
13.5. Upon expiry or termination of the contract, the Service Provider shall comply with the exit and
transition requirements defined in Section 12 (Deliverables).
13.6. The contract shall be governed by provisions relating to:
a) Asset ownership
b) Exit and transition obligations
c) Commercial benchmarking
13.7. These provisions shall remain binding for the full duration of the contract, including any
extensions.
of 60
15.1. The Service Provider shall implement end-to-end monitoring across all managed services, including
hosting, network, WAN, internet, unified communications, and disaster recovery environments to
ensure continuous visibility of availability, performance, security, and data integrity.
15.2. The Service Provider shall provide monthly service reports covering, at a minimum:
15.2.1. SLA performance and compliance
15.2.2. System uptime and availability
15.2.3. Capacity and utilisation trends
15.2.4. Security incidents and posture summary
15.2.5. All incidents, outages, and service interruptions
15.3. The Service Provider shall maintain real-time monitoring, alerting, and incident logging capabilities to
enable proactive detection, escalation, and resolution of service issues.
15.4. At contract termination or expiry, the Service Provider shall submit a comprehensive end-of-contract
report detailing:
15.4.1. Overall service performance against SLAs
of 60
Special Conditions
Source: NHBRC 08 2026 TOR Managed Infrastructure Solution 1.pdf (RFP)Terms and Conditions: Bidders must be registered on the CSD and remain registered if successful, be tax compliant and provide annual Tax Clearance Certificates. NHBRC reserves the right to amend, modify, or withdraw the RFP, carry out site inspections, and require formal presentations. Bids are binding and irrevocable for 90 days. No entity may be involved in more than one bid. Material changes in bidder control require prior written approval. Briefing session information forms part of the bid. NHBRC may waive irregularities. Bids received after closing date will be rejected. Bidders may be disqualified for non-submission of mandatory documents or irregularities. All costs associated with bid preparation are the bidder's responsibility. The RFP is confidential and for the sole purpose of responding.
Section
Source: NHBRC 08 2026 TOR Managed Infrastructure Solution 1.pdfThe evaluation criteria are not fully detailed in the provided text. However, the RFP indicates that bidders must demonstrate proven experience in delivering similar projects within the last five (5) years, and must provide a comprehensive proposal including key personnel details and project references. The NHBRC reserves the right to conduct benchmarking reviews during the contract period to ensure continued value for money. Specific evaluation weights or scoring methodology are not stated in the provided text.
Important Dates
Source: SBD FORMS_ 1 4 and 6.1. 3.1 .pdf (RFP){"closingDate":"02 OCTOBER 2026","closingTime":"11H00","briefingSession":"{"date":"11 SEPTEMBER 2026","time":"11:00","venue":"E: 11 SEPTEMBER 2026","is_compulsory":true}"}
Briefing Session
Source: SBD FORMS_ 1 4 and 6.1. 3.1 .pdf (RFP)Non-compulsory briefing session: 11 September 2026, 11:00, online via Microsoft Teams (link provided).
Contact Information
Source: SBD FORMS_ 1 4 and 6.1. 3.1 .pdf (RFP){"name":"Mr. Bernard Kekana and Mr","email":"[email protected]","phone":"011317 0114","department":"/ PUBLIC ENTITY NHBRC CONTACT PERSON","address":"ED ONLINE VIA ETENDER"}
Evaluation Criteria
Source: SBD FORMS_ 1 4 and 6.1. 3.1 .pdf (RFP)Bidders must be registered on the Central Supplier Database (CSD) and provide a CSD number or a SARS Tax Compliance Status (TCS) PIN. Bidders must be tax compliant. Bidders must complete and sign the SBD 4 (Bidder's Disclosure) and SBD 6.1 (Preference Points Claim) forms. Bidders listed on the Register for Tender Defaulters or the List of Restricted Suppliers will be disqualified. Bidders must not have engaged in collusive bidding practices. Foreign suppliers must answer the questionnaire in SBD 1 Part B. The bidder must provide proof of authority to sign the bid (e.g., resolution of directors).
Pricing Schedule
Source: SBD FORMS_ 1 4 and 6.1. 3.1 .pdf4.3. Name of company/firm...............................................................................
4.4. Company registration number: .....................................................................
4.5. Type of company/ firm
Partnership/Joint Venture / Consortium
One-person business/sole propriety
Close corporation
Public Company
Personal Liability Company
(Pty) Limited
Non-Profit Company
State Owned Company
[Tick applicable box]
of 12
of 12
4.6. I, the undersigned, who is duly authorised to do so on behalf of the company/firm,
certify that the points claimed, based on the specific goals as advised in the tender,
qualifies the company/ firm for the preference(s) shown and I acknowledge that:
i) The information furnished is true and correct;
ii) The preference points claimed are in accordance with the General Conditions as
indicated in paragraph 1 of this form;
iii) In the event of a contract being awarded as a result of points claimed as shown
in paragraphs 1.4 and 4.2, the contractor may be required to furnish documentary
proof to the satisfaction of the organ of state that the claims are correct;
iv) If the specific goals have been claimed or obtained on a fraudulent basis or any
of the conditions of contract have not been fulfilled, the organ of state may, in
addition to any other remedy it may have –
(a) disqualify the person from the tendering process;
(b) recover costs, losses or damages it has incurred or suffered as a
result of that person’s conduct;
(c) cancel the contract and claim any damages which it has suffered
as a result of having to make less favourable arrangements due
to such cancellation;
(d) recommend that the tenderer or contractor, its shareholders and
directors, or only the shareholders and directors who acted on a
fraudulent basis, be restricted from obtaining business from any
organ of state for a period not exceeding 10 years, after the audi
alteram partem (hear the other side) rule has been applied; and
(e) forward the matter for criminal prosecution, if deemed necessary.
..............................................
Signature(s) of tenderer(s)
Surname and name: ................................................................
Date: ...............................................................
Address: ...............................................................
...............................................................
...............................................................
...............................................................
of 12
Sbd 3.1
Pricing schedule – firm prices
(Purchases)
Note: only firm prices will be accepted. Non-firm prices (including prices subject to
Rates of exchange variations) will not be considered
Compliance Requirements
Source: SBD FORMS_ 1 4 and 6.1. 3.1 .pdf (RFP)Tax compliance status
Tax compliance
Tax compliance requirements
Tax compliance status (tcs) or pin may also be made via e-filing
Tax compliance status / tax compliance system pin code from the south african revenue
TCS PIN: OR CSD No
Csd report will be used to verify the ownership and calculation of
Csd report will be used to verify the ownership and
Csd report for preference
Csd number
Csd number must be provided
Central supplier database
Central supplier database (csd) to upload mandatory
Central supplier database (csd), a csd number must be provided
1.3. Bidders must register on the central supplier database (csd) to upload mandatory
Numbers; tax compliance status; and banking information for verification
Specified in the tender and csd report will be used to verify the ownership and
1.4. Where a bidder is not registered on the csd, mandatory information namely
(Business registration/ directorship/ membership/identity numbers; tax compliance
Status may not be submitted with the bid documentation. Csd report for preference
Points and company registration documents may be submitted to bidding institution.
2.3 Application for tax compliance status (tcs) or pin may also be made via e-filing. In
Points Allocation: 90 points
B-BBEE Details: Total points for Price and SPECIFIC GOALS 100
of 12
of 12
1.5 Failure on the part of a tenderer to submit proof or documentation required in terms
of this tender to claim points for specific goals with the tender, will be interpreted to
mean that preference points for specific goals are not claimed.
1.6 The organ of state reserves the right to require of a tenderer, either before a tender
is adjudicated or at any time subsequently, to substantiate any claim in regard to
preferences, in any manner required by the organ of state.
(a) “tender” means a written offer in the form determined by an organ of state in
response to an invitation to provide goods or services through price quotations,
competitive tendering process or any other method envisaged in legislation;
(b) “price” means an amount of money tendered for goods or services, and
includes all applicable taxes less all unconditional discounts;
(c) “rand value” means the total estimated value of a contract in Rand, calculated at the
time of bid invitation, and includes all applicable taxes;
(d) “tender for income-generating contracts” means a written offer in the form
determined by an organ of state in response to an invitation for the origination of
income-generating contracts through any method envisaged in legislation that will
result in a legal agreement between the organ of state and a third party that produces
revenue for the organ of state, and includes, but is not limited to, leasing and disposal
of assets and concession contracts, excluding direct sales and disposal of assets
through public auctions; and
(e) “the Act” means the Preferential Procurement Policy Framework Act, 2000 (Act No.
).
3.1. Points awarded for
B-BBEE Requirements
Source: SBD FORMS_ 1 4 and 6.1. 3.1 .pdf (RFP)This bid is subject to the Preferential Procurement Policy Framework Act 2000 and the Preferential Procurement Regulations 2022. A maximum of 20 points may be awarded for preference points, verified via the CSD report.
Contractual Terms
Source: SBD FORMS_ 1 4 and 6.1. 3.1 .pdfNO. ** (all applicable taxes included)
Required by: ........................................
At: ........................................
.......................................
Brand and model ........................................
Country of origin ........................................
Does the offer comply with the specification(s)? *YES/NO
If not to specification, indicate deviation(s) ........................................
Period required for delivery ........................................
*Delivery: Firm/not firm
Note: All delivery costs must be included in the bid price, for delivery at the prescribed destination.
** “all applicable taxes” includes value- added tax, pay as you earn, income tax, unemployment insurance fund
contributions and skills development levies.
*Delete if not applicable
of 12
Requirements
Source: SBD FORMS_ 1 4 and 6.1. 3.1 .pdf (RFP)Bidders must register on the Central Supplier Database (CSD) to upload mandatory information (business registration, directorships, identity numbers, tax compliance status, banking information). A maximum of 20 preference points may be awarded and the CSD report will be used to verify ownership and calculate points. Where a bidder is not registered on CSD, mandatory information may not be submitted with bid documentation; CSD report for preference points and company registration documents may be submitted to the bidding institution.
Section
Source: SBD FORMS_ 1 4 and 6.1. 3.1 .pdfCe points claim form in terms of the preferential
This preference form must form part of all tenders invited. It contains general information
and serves as a claim form for preference points for specific goals.
1.1 The following preference point systems are applicable to invitations to tender
the 80/20 system for requirements with a Rand value of up to R50 000 000 (all
the 90/10 system for requirements with a Rand value above R50 000 000 (all
a) The applicable preference point system for this tender is the 90/10 preference point
b) The applicable preference point system for this tender is the 80/20 preference point
c) Either the 90/10 or 80/20 preference point system will be applicable in this tender.
1.3 Points for this tender (even in the case of a tender for income-generating contracts)
(b) Specific Goals.
The maximum points for this tender are allocated as follows
Specific goals
Total points for Price and SPECIFIC GOALS 100
of this tender to claim points for specific goals with the tender, will be interpreted to
mean that preference points for specific goals are not claimed.
preferences, in any manner required by the organ of state.
Ses). A maximum points of 20 may be awarded to a bidder for preference points
Calculation of points..
Status may not be submitted with the bid documentation. Csd report for preference
Points and company registration documents may be submitted to bidding institution.
with any competitor regarding the quality, quantity, specifications, prices, including methods,
Preference points claim form in terms of the preferential
This preference form mus
Evaluation Criteria
Source: e-Submission_User Manual For Suppliers.pdf (TENDER)Bidders must have a valid Central Supplier Database (CSD) registration with a registered email address and password to access the eTender portal. They must select a valid supplier number associated with their CSD profile to apply for the bid.
Compliance Requirements
Source: e-Submission_User Manual For Suppliers.pdf (TENDER)Central Supplier Database (CSD) registered email address
Central Supplier Database (CSD) login password
Health & Safety
Source: e-Submission_User Manual For Suppliers.pdfA pop up confirming a successful submission will appear after you click Submit
The status of your submission will appear as Submitted.
Should the status be Pending, please note that you have not yet submitted all the required documents and will need to do
so to ensure a successful submission.
Click the “+” button to edit or withdraw your submission
After clicking “Edit eSubmission”, acknowledge the disclaimer pop-up by clicking “Proceed”.
Click the “Edit” button and select file or drag and drop to upload different documentation
Click “Confirm & Proceed” thereafter
After clicking “Withdraw bid” on the previous page, the application will disappear from your list.
Sets the constitutional standard for fair, equitable, transparent, competitive and cost-effective public procurement.
Relevant because this is a South African public-sector procurement opportunity.
Act 5 of 2000
Covers preferential procurement and preference-point systems used in public tenders.
Relevant because this is a South African public-sector procurement opportunity.
Act 12 of 2004
Supports anti-corruption controls and supplier integrity in procurement processes.
Relevant because this is a South African public-sector procurement opportunity.
Act 28 of 2024
Provides the national framework for public procurement across government.
Relevant because this is a South African public-sector procurement opportunity.
Act 2 of 2000
Supports access to tender records, award decisions and public-sector procurement information.
Relevant because this is a South African public-sector procurement opportunity.
Act 3 of 2000
Supports lawful, reasonable and procedurally fair administrative tender decisions.
Relevant because this is a South African public-sector procurement opportunity.
Address
27 Leeuwkop Road Sandton, Sunninghill, Johannesburg, 2157, South Africa
Source confidence
High source confidence
Official source
eTenders.gov.za
Documents found
3
Last checked
08 Sept 2026
AI status
Enhanced
Data conflicts
None detected
This tender has strong source evidence, including source metadata and supporting tender information synced from the government tender portal.
Tenders SA is not the issuing authority. All tenders are automatically synced from the official government tender portal. Always confirm final submission details, closing dates, briefing sessions, eligibility requirements, and documents on the official government portal before applying.
Contact
011-317-0448[email protected]www.nhbrc.org.za27 Leeuwkop Road Sandton, Sunninghill, Johannesburg, 2157, South Africa
Key Personnel
Provinces Active
Industries
Get deep intelligence on Computer programming, consultancy and related activities. Unlock full pricing strategies, bid frequency, and historical win rates.
Learn how to submit a winning bid with these related articles
In 2026, General contractors operating in the Eastern Cape must prioritize compliance with COIDA (Compensation for Occupational Injuries and Diseases Act) registration and Letters of Good Standing. With the Department of Employment and Labour intensifying enforcement, and government tenders increasingly scrutinizing workforce-related compliance, failure to maintain valid documentation can disqualify bids before evaluation even begins. As public sector procurement in the province continues to demand higher standards of legal and financial integrity, suppliers must treat these requirements as non-negotiable gateways to participation.
How small office supplies, stationery, and general goods suppliers use Joint Ventures to win government procurement contracts by combining inventory with B-BBEE credentials.
How the Protection of Personal Information Act affects tender submissions, data handling, and supplier contracts with government. A practical POPIA compliance guide for South African tender bidders covering lawful processing, data subject rights, and consequences of non-compliance.
A meticulously organised tender submission can be the difference between a winning bid and one that hits the rejection pile. Learn how to package, structure, and present your tender response for maximum evaluator impact on South African government contracts.
💡 Want more tendering tips and strategies?
Explore Our Blog