Broad-Based Black Economic Empowerment Act (B-BBEE Act)
Act 53 of 2003
Provides the empowerment-compliance context often used in public-sector supplier evaluation.
Relevant because this is a South African public-sector procurement opportunity.
Issuing Organization
South African Civil Aviation Authority (SACAA)Location
Gauteng
Closing Date
05 Oct 2026
Documents available on tender detail page
Tender Type
Request for Quotation
Delivery Location
BYLS Bridge Office Park, Olievenhoutbosch Road & Jean Ave - Centurion - Pretoria - 0062
Organization Type
GOVERNMENT
Published
23 Sept 2026
OCDS Reference
ocds-9t57fa-171528
The south african civil aviation authority (SACAA) requires a once-off corporate threat assessment across its entire IT environment, covering internal networks, external-facing systems, web applications, cloud platforms, and business-critical assets. The successful bidder must deliver a detailed threat analysis report with risk ratings, remediation recommendations, and a prioritised mitigation roadmap, plus three audience-specific presentations and a remediation assessment. Bidders must score at least 80 out of 100 on functionality to proceed to the 80/20 price and b-bbee evaluation, and must submit a three-envelope bid by 11:00 on 05 october 2026.
Closing: 05 October 2026 at 11:00, deposited in Tender Box 1 at SACAA head office, BYLS Bridge Office Park, Olievenhoutbosch Road & Jean Ave, Centurion, 0062. Late bids are disqualified.
Mandatory compliance: CSD registration (supplier number), completed and signed SBD 1, SBD 4, and SBD 6.1. Incomplete or unsigned forms may invalidate the bid.
Functionality minimum: 80 out of 100 points. References: 5 letters (30 pts), 4 (20 pts), 3 (10 pts) for corporate threat assessment services in the last 3 years. Certifications: CEH, OSCP, CISSP (10 pts each). Technical methodology (20 pts) for internal and external penetration testing.
B-BBEE specific goals (20 pts): Level 1 = 20, 2 = 18, 3 = 14, 4 = 12, 5 = 5, 6 = 6, 7 = 4, 8 = 2, non-compliant = 0. Submit B-BBEE certificate or sworn affidavit (EMEs/QSEs) to claim points.
Three-envelope submission: Envelope 1 – mandatory documents; Envelope 2 – technical proposal (original + copy); Envelope 3 – pricing schedule (original + copy) with detailed breakdown. Mark each envelope with RFQ reference number and bidder name.
Office park access code: Must be arranged before submission with Betty Monyeki (082 885 4270) or Cynthia Motaung (083 461 6534).
Tax compliance: Provide SARS TCS PIN or printed certificate; each consortium/JV/subcontractor party must submit separately. No bids from persons in service of the state or companies with such directors/members.
Continue with tenders sharing this issuer, category, or province.
Return to this tender’s issuing organisation, province, or category.
Continue with tenders sharing this issuer, category, or province.
Date & Time
Monday, 05 October 2026 - 11:00
Venue
null
Categories
Request for Quotation
BYLS Bridge Office Park, Olievenhoutbosch Road & Jean Ave - Centurion - Pretoria - 0062
Tenders in this industry often require registration with these bodies.
Recommended Certifications
Having these can improve your winning chances: CA(SA) - Chartered Accountant, PMI-PMP (Project Management Professional), Prince2 Practitioner, Six Sigma Certification
AI Document Analysis Stages
Description
Source: RFQ for Corporate Threat Assessments - 23 September 2026.pdf (RFQ)23 Sept
2026
Tender Published
Tender was published
05 Oct
2026
Closing Date
Tender closing date
These references help suppliers understand the public-procurement framework around this opportunity. They are generated from the tender category, issuing organisation type and procurement context.
These rules commonly apply to South African public-sector procurement.
Act 53 of 2003
Provides the empowerment-compliance context often used in public-sector supplier evaluation.
Relevant because this is a South African public-sector procurement opportunity.
Act 108 of 1996 (s217)
This is general procurement context, not legal advice. Always verify requirements in the official tender documents and issuing authority notices.
RFQ for Corporate Threat Assessments - 23 September 2026.pdf
The South African Civil Aviation Authority (SACAA) requires a one-time corporate threat assessment of its entire IT environment, including internal networks, external systems, web applications, and cloud platforms, to identify vulnerabilities and strengthen cyber resilience.
To download these documents and access AI-powered analysis, visit the main tender page.
Organization
South African Civil Aviation Authority (SACAA)Contact Person
Rudolph Mohlala
Phone
011-545-1720
Matched by category & region
Free guidance to prepare before you bid
Not sure if your business is ready for this tender? Check CSD, CIDB, and B-BBEE requirements, run a readiness assessment, and move from opportunity to submission.
Open Supplier Readiness HubLearn how to submit a winning bid with these related articles
Median Estimate
R 198 375
Range
Based on 25 comparable awarded tenders. Companies with similar profiles typically bid near the median.
* Estimates are based on historical data and do not guarantee actual award values.
We refine every tender document through these stages so you can brief your team and prepare your bid with confidence. Anything marked as "in progress" will be upgraded automatically — no action required from you.
SACAA is a Schedule 3A public entity under the PFMA, mandated to regulate civil aviation safety and security. This RFQ seeks a service provider for a comprehensive corporate threat assessment across SACAA's IT environment.
Important Dates
Source: RFQ for Corporate Threat Assessments - 23 September 2026.pdf (RFQ)Closing date: 05 October 2026 at 11:00.
No briefing or site visit mentioned.
Contact Information
Source: RFQ for Corporate Threat Assessments - 23 September 2026.pdf (RFQ)Bidding procedure enquiries:
Technical enquiries:
Office park access code:
Submission address:
South African Civil Aviation Authority
BYLS Bridge Office Park
Olievenhoutbosch Road & Jean Ave
Centurion, 0062
Submission Guidelines
Source: RFQ for Corporate Threat Assessments - 23 September 2026.pdf (RFQ)Submission method: sealed envelope/package deposited in Tender Box 1 at the SACAA head office foyer.
Address: South African Civil Aviation Authority, BYLS Bridge Office Park, Olievenhoutbosch Road & Jean Ave, Centurion, 0062.
Closing: 05 October 2026 at 11:00.
Three-envelope system:
Documents must be neat and bound; SACAA not responsible for loss.
Mark envelope with RFQ reference number and bidder company name.
Returnable forms (all must be completed and signed):
Disqualification risks:
Evaluation Criteria
Source: RFQ for Corporate Threat Assessments - 23 September 2026.pdf (RFQ)Evaluation stages:
Technical Specifications
Source: RFQ for Corporate Threat Assessments - 23 September 2026.pdf (RFQ)Scope: Comprehensive Corporate Threat Assessment across SACAA's entire IT environment, including internal networks, external-facing systems, web applications, cloud platforms, business critical assets, and associated digital infrastructure.
Frameworks: ISO/IEC 27001, OWASP Top 10 (2025), NIST SP 800-115.
Deliverables:
Testing scope:
Service duration: once off.
Methodology
Source: RFQ for Corporate Threat Assessments - 23 September 2026.pdf (RFQ)Bidder must provide detailed methodology for internal and external penetration testing. Testing approach: grey box, with internal assessment attempting perimeter bypass first. Deliver three audience-specific presentations and a remediation assessment.
Experience & Qualifications
Source: RFQ for Corporate Threat Assessments - 23 September 2026.pdf (RFQ)Bidder must be suitably qualified and experienced. Provide contactable reference letters from clients for corporate threat assessment services in the last 3 years (5 letters for full points).
Quality Management
Source: RFQ for Corporate Threat Assessments - 23 September 2026.pdf (RFQ)Testing must follow OWASP framework covering listed vulnerabilities. Certifications required: CEH, OSCP, CISSP.
Financial Requirements
Source: RFQ for Corporate Threat Assessments - 23 September 2026.pdf (RFQ)Pricing schedule must be submitted separately (Envelope 3) with detailed breakdown.
No bid security, bonds, guarantees, or payment terms specified.
Compliance Requirements
Source: RFQ for Corporate Threat Assessments - 23 September 2026.pdf (RFQ)Mandatory:
Contractual Terms
Source: RFQ for Corporate Threat Assessments - 23 September 2026.pdf (RFQ)Service is once off. Contract subject to GCC and PPPFA. Successful bidder must sign SBD 7 (Contract Form).
Section
Source: RFQ for Corporate Threat Assessments - 23 September 2026.pdf (RFQ)Functionality evaluation: references (max 30), penetration testing certifications (max 50), technical approach (max 20). Minimum 80/100 to proceed. Price and specific goals: 80/20 system.
Sets the constitutional standard for fair, equitable, transparent, competitive and cost-effective public procurement.
Relevant because this is a South African public-sector procurement opportunity.
Act 5 of 2000
Covers preferential procurement and preference-point systems used in public tenders.
Relevant because this is a South African public-sector procurement opportunity.
Act 12 of 2004
Supports anti-corruption controls and supplier integrity in procurement processes.
Relevant because this is a South African public-sector procurement opportunity.
Act 28 of 2024
Provides the national framework for public procurement across government.
Relevant because this is a South African public-sector procurement opportunity.
Act 2 of 2000
Supports access to tender records, award decisions and public-sector procurement information.
Relevant because this is a South African public-sector procurement opportunity.
Act 3 of 2000
Supports lawful, reasonable and procedurally fair administrative tender decisions.
Relevant because this is a South African public-sector procurement opportunity.
Address
BYLS Bridge Office Park, Olievenhoutbosch Road & Jean Ave - Centurion - Pretoria - 0062
Source confidence
High source confidence
Official source
eTenders.gov.za
Documents found
1
Last checked
01 Oct 2026
AI status
Enhanced
Data conflicts
None detected
This tender has strong source evidence, including source metadata and supporting tender information synced from the government tender portal.
Tenders SA is not the issuing authority. All tenders are automatically synced from the official government tender portal. Always confirm final submission details, closing dates, briefing sessions, eligibility requirements, and documents on the official government portal before applying.
💡 Want more tendering tips and strategies?
Explore Our BlogGet deep intelligence on Services: Professional. Unlock full pricing strategies, bid frequency, and historical win rates.