Broad-Based Black Economic Empowerment Act (B-BBEE Act)
Act 53 of 2003
Provides the empowerment-compliance context often used in public-sector supplier evaluation.
Relevant because this is a South African public-sector procurement opportunity.
Documents available on tender detail page
Tender Type
Request for Bid(Open-Tender)
Delivery Location
420 Witch-Hazel Avenue, Eco Glades 2 - Centurion - Pretoria - 0046
Organization Type
GOVERNMENT
Published
10 Sept 2026
OCDS Reference
ocds-9t57fa-169913
The road accident fund (raf) is procuring managed threat detection and response (tdr) services, including 24/7/365 cybersecurity monitoring, incident response, threat hunting, and siem management, for a period of five years. Bidders must provide a service based on the raf's existing in-house microsoft sentinel platform engage, with a non-compulsory briefing session and a closing date of 9 october 2026. The most consequential requirement is the provision of a full 24/7/365 managed security operations centre (soc) service, including incident response with aggressive service-level targets, for five years.
Bids must be hand-delivered or couriered to the tender box at Road Accident Fund, Eco Glades 2 Office Park, 420 Witch-hazel Avenue, Centurion, 0046, by 09 October 2026 at 11:00 AM. Faxed or emailed bids will not be accepted.\nA non-compulsory briefing session will be held on Microsoft Teams on 22 September 2026 at 11:00 AM; the meeting link is provided in the tender document.\nBidders must submit all required SBD forms (SBD 1, SBD 3.3, SBD 4, SBD 5, SBD 6.1) completed and signed, along with a valid Tax TCS PIN or CSD registration, and be registered on the Central Supplier Database (CSD).\nThe service provider will be responsible for a full managed 24/7/365 SOC service, including monitoring the RAF's Microsoft Sentinel SIEM, cloud environments (AWS, Azure, Oracle), and on-premises infrastructure, with incident response and SOAR automation.\nThe SOC must meet specific premises requirements: access control (fingerprint or token/card), backup power restored within one minute, a business continuity plan, and a valid fire detection system certificate (service certificate not older than 1 year).\nThe service provider must have a dedicated SOC team with at least three tiers of support, including at least one SOC service delivery manager and one SOC threat management lead.\nThe service provider must respond to incidents within the following timeframes: Priority 1 – response 15 minutes, resolution 1 hour; Priority 2 – response 30 minutes, resolution 2 hours; Priority 3 – response 45 minutes, resolution 6 hours; Priority 4 – response 60 minutes, resolution 10 hours.\nThe bidder must hold Professional Indemnity insurance that covers privacy breach and cyber liability, and must have a business continuity management plan available for inspection by the RAF.\nBids must remain valid for 90 days from the closing date, and the successful bidder may be required to sign a contract form (SBD 7).\nBidders must allow the RAF to conduct privacy, information security, and compliance audits, and must not transfer or store RAF information outside South Africa without prior written approval.
Continue with tenders sharing this issuer, category, or province.
Return to this tender’s issuing organisation, province, or category.
Continue with tenders sharing this issuer, category, or province.
Date & Time
Friday, 09 October 2026 - 11:00
Venue
https://teams.microsoft.com/meet/351818207347668?p=8tu6wsXapZXCYCYNSL
Categories
Request for Bid(Open-Tender)
420 Witch-Hazel Avenue, Eco Glades 2 - Centurion - Pretoria - 0046
AI Document Analysis Stages
Description
10 Sept
2026
Tender Published
Tender was published
09 Oct
2026
Closing Date
Tender closing date
These references help suppliers understand the public-procurement framework around this opportunity. They are generated from the tender category, issuing organisation type and procurement context.
These rules commonly apply to South African public-sector procurement.
Act 53 of 2003
Provides the empowerment-compliance context often used in public-sector supplier evaluation.
Relevant because this is a South African public-sector procurement opportunity.
Act 108 of 1996 (s217)
This is general procurement context, not legal advice. Always verify requirements in the official tender documents and issuing authority notices.
RFB RAF 2026 00059 Threat Detection and Response Services 10 09 2026.pdf
The Road Accident Fund (RAF) is procuring a managed Threat Detection and Response (TDR) service for a five-year period. The successful bidder will operate and manage the RAF's existing in-house Microsoft Sentinel SIEM solution, providing 24/7/365 monitoring, detection, incident response, threat hunting, and related security operations centre (SOC) services.
To download these documents and access AI-powered analysis, visit the main tender page.
Matched by category & region
Free guidance to prepare before you bid
Not sure if your business is ready for this tender? Check CSD, CIDB, and B-BBEE requirements, run a readiness assessment, and move from opportunity to submission.
Open Supplier Readiness HubMedian Estimate
R 5 911 575
Range
Based on 25 comparable awarded tenders. Companies with similar profiles typically bid near the median.
* Estimates are based on historical data and do not guarantee actual award values.
We refine every tender document through these stages so you can brief your team and prepare your bid with confidence. Anything marked as "in progress" will be upgraded automatically — no action required from you.
The Road Accident Fund (RAF) is a Schedule 3A Public Entity established in terms of the Road Accident Fund Act, 56 of 1996. The RAF provides compulsory motor vehicle accident insurance to all users of South African roads, including foreigners who have accidents within the country. The RAF has Customer Experience Centres situated in each province. The service must provide a Threat Detection and Response (TDR) service that includes a Security Operations Centre (SOC) operating 24/7, with proactive threat hunting, incident response, and SOAR automation. The service must leverage open-source detection use cases such as Sigma, and create custom rules for emerging threats specific to the South African government and insurance sectors. The service must include continuous skills transfer to 10 cybersecurity personnel throughout the contract, including during and after implementation. The service must also provide SOC escalation procedures and escalation matrices.
Important Dates
Source: RFB RAF 2026 00059 Threat Detection and Response Services 10 09 2026.pdf (TENDER){"closingDate":"09 OCTOBER 2026","closingTime":"11:00 AM","briefingSession":"{"date":"22 SEPTEMBER 2026","time":"11:00 AM","venue":"E AND TIME: 22 SEPTEMBER 2026","is_compulsory":true}"}
Briefing Session
Source: RFB RAF 2026 00059 Threat Detection and Response Services 10 09 2026.pdf (TENDER)NON-COMPULSORY BRIEFING SESSION DATE AND TIME: 22 SEPTEMBER 2026 @ 11:00 AM. A NON-COMPULSORY BRIEFING SESSION WILL BE HELD ON TEAMS: https://teams.microsoft.com/meet/351818207347668?p=8tu6wsXapZXCYCYNSL
Contact Information
Source: RFB RAF 2026 00059 Threat Detection and Response Services 10 09 2026.pdf (TENDER){"name":"Mr Elias","email":"[email protected]","phone":null,"department":"of Trade and Industry (dti) is","address":"All enquiries regarding this bid must be directed to the Supply Chain Management Office"}
Submission Guidelines
Source: RFB RAF 2026 00059 Threat Detection and Response Services 10 09 2026.pdf (TENDER)Returnable Documents: SBD 1: Completed, attached and signed, SBD 4: Completed, attached and signed, SBD 6.1: Completed, attached and signed, Proof of Construction Industry Development Board (CIDB), Provide Tax TCS Pin to verify Tax Status: Attached, involved, each party must submit a separate Tax TCS Pin.), Registered on the Central Supplier Database of National, https://secure.csd.gov.za/),
Evaluation Criteria
Source: RFB RAF 2026 00059 Threat Detection and Response Services 10 09 2026.pdf (TENDER)Bidders must be registered on the National Treasury Central Supplier Database (CSD). Bidders must be tax compliant with SARS; if non-compliant, they will be allowed seven working days to rectify before disqualification. Bidders must submit a SARS Tax Compliance Status (TCS) PIN or CSD number. Bidders must complete and sign all required Standard Bidding Documents (SBD forms): SBD 1 (Invitation to Bid), SBD 3.1/3.2/3.3 (Pricing Schedule), SBD 4 (Declaration of Interest), SBD 5 (National Industrial Participation Programme), SBD 6.1 (Preference Points Claim Form). Bidders must provide proof of authority to sign (e.g., company resolution). Bidders must not be persons in the service of the state, nor have directors who are. Bidders listed on the National Treasury register of Restricted Suppliers or Tender Defaulters will be automatically disqualified. Bidders must have a business continuity management plan available for inspection. Bidders must have Professional Indemnity cover including privacy breach and cyber liability extensions. Bidders must not transfer, store, or process RAF information outside South Africa without prior written approval. Bidders must permit RAF audits of information processing. Bidders must implement Privacy by Design and Privacy by Default principles. Bidders must protect electronically stored information with encryption, authentication, logging, and monitoring. Bidders must submit a joint venture agreement if applicable. Bidders must provide a Tax TCS Pin for each party in a consortium/joint venture/sub-contractor arrangement.
Technical Specifications
Source: RFB RAF 2026 00059 Threat Detection and Response Services 10 09 2026.pdf (TENDER)Procurement of a threat detection and response services for the raf for a period of
Five (5) years.
Methodology
Source: RFB RAF 2026 00059 Threat Detection and Response Services 10 09 2026.pdf (TENDER)The service must provide: full management of the SIEM architecture (excluding licensing costs); onboarding of new data sources (Syslog, API, Cloud logs, Agents); health monitoring of data connectors and log ingestion pipelines to ensure no visibility gaps; continuous optimisation and tuning of detection rules to reduce alert fatigue; mapping of all detection use cases to the MITRE ATT&CK Framework; custom rule creation based on emerging threats specific to the South African government and insurance sectors; execution of Incident Response (IR) playbooks for containment and eradication; implementation and management of SOAR (Security Orchestration, Automation, and Response) to automate repetitive tasks (blocking IPs, isolating compromised endpoints); deep-dive forensic analysis for high-criticality incidents; incident triage and analysis to build capability; incident containment and remediation; active response & lockdown with pre-approved actions; root cause analysis (RCA) post-incident; integration of global threat intelligence feeds; threat hunting using advanced security technologies and techniques; threat response design of manual, semi-automated and automated responses; service migration with a structured 30-to-60-day transition plan, knowledge transfer, migration of custom workbooks/dashboards, validation of alerting logic; enterprise integration for seamless data sharing, workflows, single sign-on, and centralised management; and comprehensive reporting with metrics such as MTTD and MTTR and dashboards.
Experience & Qualifications
Source: RFB RAF 2026 00059 Threat Detection and Response Services 10 09 2026.pdf (TENDER)all foreigners who may have had accidents within the borders of the country. The RAF head
office is located in Centurion, Pretoria; with Customer Experience Centres situated in each
province around the country.
Quality Management
Source: RFB RAF 2026 00059 Threat Detection and Response Services 10 09 2026.pdf (TENDER)2.1. The bidder/s must be an eligible, registered service provider/s in terms of the applicable laws
of the country.
2.2. The bidder/s must have a business continuity management plan, which must be available for
inspection by the RAF during the subsistence of rendering services to the RAF.
2.3. The Evaluation Criteria that are published with this Request for Proposal/ Bids will be used to
assess bidders’ responses and no amendment shall be made after the closing date of a bid.
include:
schedule.
landscape and threat management requirements.
▪ Microsoft Entra ID (Azure AD)
▪ RAF Security Logging data sources
▪ Identity and Access Management (IAM) and Privileged Access Management
(PAM) systems
▪ Configuration of TDR data sources, data collection rules and data retention
policies
▪ Implementation of TDR use cases and automated response workflows
▪ Testing, including User Acceptance Testing (UAT).
▪ Go-live support and hyper-care support for a defined stabilisation period
(minimum period to be proposed by bidder).
▪ Implementation duration
▪ Key deliverables
▪ Resource allocation
▪ Project governance structure
4.15.2.2 Post Implementation professional services
The bidder is expected to provide 24/7/365 managed TDR services; these professional
services may include:
operational load.
4.15.3 Training and Onboarding
Pricing Schedule
Source: RFB RAF 2026 00059 Threat Detection and Response Services 10 09 2026.pdf (TENDER)https://teams.microsoft.com/meet/351818207347668?p=8tu6wsXapZXCYCYNSL
Closing date: 09 october 2026 @ 11h00 AM
Note: Faxed and/or Emailed Proposals/ bids will not be accepted, only hand delivered and
couriered Proposals/ bids must be deposited in the tender box on or before the closing date and
time.
Table of contents for bid RAF/2026/00059
Part a: invitation to bid
Part b: terms and conditions for bidding
Sbd 3.3: Pricing schedule (professional services)
Sbd 4: declaration of interest
Sbd 5: national industrial participation programme
Sbd 6.1: Preference points claim form
The service of the state.”
Nb: failure to provide / or comply with any of the above particulars may render the bid invalid.
Signature of bidder:...................................................
Capacity under which this bid is signed:...................................................
(Proof of authority must be submitted e.g. company resolution)
Sbd 3.1
Pricing schedule – firm prices
(Purchases)
Note: only firm prices will be accepted. Non-firm prices (including prices subject
To rates of exchange variations) will not be considered
Financial Requirements
Source: RFB RAF 2026 00059 Threat Detection and Response Services 10 09 2026.pdf (TENDER)Bid Bond: performance guarantee to the dti;
d. The contractor will submit a business concept for consideration and approval by
the dti;
e. Upon approval of the business concept by the dti, the contractor will submit
detailed business plans outlining the business concepts;
f. The contractor will implement the business plans;
Compliance Requirements
Source: RFB RAF 2026 00059 Threat Detection and Response Services 10 09 2026.pdf (TENDER)Cybersecurity
Initial triage to filter false positives and escalate "True Positive" incidents.
Contextualised alerting based on RAF’s business risk and asset criticality.
Real-time monitoring and threat detection of the RAF’s on-premises and cloud-based systems, applications, and infrastructure. All incidents must be promptly identified, escalated, and addressed.
Monitoring the RAF’s environment, including cloud services (AWS, Azure, and Oracle cloud) and on-premises for potential security incidents and unauthorized activity.
Log Management: the SOC should be able to collect and retain logs from multiple systems and generate reports that can be used to provide a holistic view of the environment.
Threat Intelligence Integration: integrate global threat intelligence feeds to detect and respond Category Description Indicate the section of the proposal that addresses this to emerging threats proactively. The service must provide
Full management of the SIEM architecture (excluding licensing costs). SIEM Engineering &
Onboarding of new data sources (Syslog, API, Data Onboarding Cloud logs, Agents).
Health monitoring of data connectors and log ingestion pipelines to ensure no visibility gaps. Detection Engineering & The service must provide: Tuning
Mapping of all detection use cases to the MITRE ATT&CK Framework.
Custom rule creation based on emerging threats specific to the South African government and insurance sectors.
Leveraging open-source detection use cases such as Sigma. The service must provide
Execution of Incident Response (IR) playbooks for containment and eradication. Incident Response &
Implementation and management of SOAR SOAR Automation (Security Orchestration, Automation, and Response) to automate repetitive tasks (e.g., blocking IPs, isolating compromised endpoints).
Deep-dive forensic analysis for high-criticality incidents.
Incident Triage and Analysis: prompt triage and analyse security incidents in the environment to Category Description Indicate the section of the proposal that addresses this determine severity, scope, and impact.
Incident Containment and Remediation: contain and remediate security incidents in the environment to minimise their impact and duration, including the execution of Incident Response (IR) playbooks for containment and eradication.
Communication and Coordination: communicate and coordinate with internal and external stakeholders to resolve security incidents and address security risks.
Active Response & Lockdown: In the event of a confirmed breach (like the current stolen access information), the service provider should have the authority to isolate infected machines or lock compromised accounts immediately, through pre-approved TDR actions and operating models.
Root Cause Analysis (RCA): Post-incident investigations to determine how the breach occurred and how to harden the system against future occurrences.
Crisis Management Support: Access to a dedicated Incident Response team for large- scale events. Threat Hunting The service must
Use advanced security technologies and techniques to conduct ongoing threat hunting activities to identify and mitigate potential security threats in the environment. Category Description Indicate the section of the proposal that addresses this
Provide ongoing threat intelligence and analysis to inform the RAF’s security posture and decision-making processes.
Manage Threats: Integrate the RAF’s cybersecurity solutions to automate responses to identified threats that pose risks to the RAF environment. Threat Response The service must
Provide design of implementation of manual, semi-automated and automated responses and recovery actions to detected threats and cyberattacks.
Activate incident response plans in the event of cybersecurity incidents. Service Migration The service must include
A structured 30-to-60-day transition plan from the current service provider.
Knowledge transfer, migration of existing custom workbooks/dashboards, and validation of current alerting logic. Enterprise Integration The service must
Cater for threat intelligence integration, to allow for seamless and automated data sharing between the existing security tools and the TDR platform, thus eliminating manual processes and reducing the risk of human error.
Points Allocation: 3 points
B-BBEE Details: Postal address
..........................................................................................
....................................................................................
Signature.....................................Name (in print)...................................
Date..................................................
Sbd 6.1
Preference points claim form in terms of the preferential procurement
Regulations 2022
This preference form must form part of all tenders invited. It contains general information and serves
as a claim form for preference points for specific goals.
Nb: before completing this form, tenderers must study the general
Conditions, definitions and directives applicable in respect of the
Tender and preferential procurement regulations, 2022
1.1 The following preference point systems are applicable to invitations to tender:
applicable taxes included); and
applicable taxes included).
1.2 To be completed by the organ of state
(delete whichever is not applicable for this tender).
a) The applicable preference point system for this tender is the 80/20 or 90/10 preference
point system.
1.3 Points for this tender (even in the case of a tender for income-generating contracts) shall be
awarded for:
(a) Price; and
(b) Specific Goals.
1.4 To be completed by the organ of state:
The maximum points for this tender are allocated as follows:
Points points
Price 80 90
Specific goals 20 10
Total points for Price and SPECIFIC GOALS 100 100
1.5 Failure on the part of a tenderer to submit proof or documentation required in
Health & Safety
Source: RFB RAF 2026 00059 Threat Detection and Response Services 10 09 2026.pdf (TENDER)The SOC command centre premises must meet the following requirements: Access Controlled - minimum: Fingerprint or Token/Card Access control; Power Failure Backup - backup power restored within a minute; Business Continuity Plan; Fire Detection System - certificate of compliance and certificate of service not older than 1 year from the date of the site visit.
Contractual Terms
Source: RFB RAF 2026 00059 Threat Detection and Response Services 10 09 2026.pdf (TENDER)The service provider/s agrees to indemnify and hold the Fund harmless from and against any claims, losses, damages, or expenses incurred as a result of any breach arising out of or attributable to the service provider’s negligent acts or omissions.
Requirements
Source: RFB RAF 2026 00059 Threat Detection and Response Services 10 09 2026.pdf (TENDER)The bidder/s must be an eligible, registered service provider/s in terms of the applicable laws of the country. The bidder/s must have a business continuity management plan, which must be available for inspection by the RAF during the subsistence of rendering services to the RAF. Companies or Directors included on the National Treasury register of Restricted Suppliers and/or Tender Defaulters will be automatically disqualified from the bidding process. As prescribed all Standard Bidding Documents (SBD Forms – Returnable Documents) must be fully completed and duly signed. All Returnable Documents must be submitted with the proposal on the closing date of the bid. The RAF will confirm the following prior to any award being made: that the bidder/s is/are registered on the National Treasury Central Supplier Database (CSD); the bidder’s tax status is compliant with the South African Revenue Service (SARS), in cases where the recommended bidder/s is/are non-compliant with SARS, the bidder/s will be allowed seven (7) working days to rectify their tax matters, if the bidder/s fails to rectify their tax matters, they will be disqualified once the 7th working day period lapses. The bidder/s shall have Professional Indemnity cover, which must be available prior to the award, which shall extend to include Privacy breach and cyber liability (extension/endorsement). The Bidder/s must implement or consider the principles of Privacy by Design and Privacy by Default when reviewing, redesigning and recommending business processes. The Bidder/s must ensure that all information stored electronically is protected through appropriate encryption, authentication, logging and monitoring controls where applicable. The Bidder/s must not transfer, store or process RAF information outside the Republic of South Africa without the RAF's prior written approval and compliance with applicable legal requirements. The Bidder/s must permit the RAF, or its authorised representatives, to conduct privacy, information security and compliance assessments or audits relating to the processing of RAF information.
Section
Source: RFB RAF 2026 00059 Threat Detection and Response Services 10 09 2026.pdf (TENDER)The document includes a cross-referencing matrix that maps proposal sections to requirements, but it is noted that this matrix does not form part of the evaluation and will not be scored independently. The evaluation will consider the completeness and signing of all required SBD forms. The preference point system (80/20 or 90/10) may apply, but the specific system is not stated in the document.
Sets the constitutional standard for fair, equitable, transparent, competitive and cost-effective public procurement.
Relevant because this is a South African public-sector procurement opportunity.
Act 5 of 2000
Covers preferential procurement and preference-point systems used in public tenders.
Relevant because this is a South African public-sector procurement opportunity.
Act 12 of 2004
Supports anti-corruption controls and supplier integrity in procurement processes.
Relevant because this is a South African public-sector procurement opportunity.
Act 28 of 2024
Provides the national framework for public procurement across government.
Relevant because this is a South African public-sector procurement opportunity.
Act 2 of 2000
Supports access to tender records, award decisions and public-sector procurement information.
Relevant because this is a South African public-sector procurement opportunity.
Act 3 of 2000
Supports lawful, reasonable and procedurally fair administrative tender decisions.
Relevant because this is a South African public-sector procurement opportunity.
Address
2, Eco Glades Office Park, 420 Witch-Hazel Ave, Centurion, Pretoria, 0046, South Africa
Source confidence
High source confidence
Official source
eTenders.gov.za
Documents found
1
Last checked
12 Sept 2026
AI status
Enhanced
Data conflicts
None detected
This tender has strong source evidence, including source metadata and supporting tender information synced from the government tender portal.
Tenders SA is not the issuing authority. All tenders are automatically synced from the official government tender portal. Always confirm final submission details, closing dates, briefing sessions, eligibility requirements, and documents on the official government portal before applying.
Contact
012-649-2023[email protected]www.raf.co.za2, Eco Glades Office Park, 420 Witch-Hazel Ave, Centurion, Pretoria, 0046, South Africa
Key Personnel
Learn how to submit a winning bid with these related articles
Win consulting, legal, accounting, and engineering service contracts with government. Learn registration requirements and proposal strategies.
Win government insurance, banking, actuarial, and financial consulting contracts. FSCA licensing requirements and tender strategies for financial service providers.
Master the art of the consulting bid. How to structure your methodology, price your services competitively, and score maximum evaluation points.
A professional guide for law firms to join the provincial and municipal legal panels in Gauteng, covering compliance, specialization, and bidding.
💡 Want more tendering tips and strategies?
Explore Our BlogGet deep intelligence on Other service activities. Unlock full pricing strategies, bid frequency, and historical win rates.