ICT Security Penetration and Vulnerability Assessment Services
Asisipho Matomane
In plain English
An ICT Security penetration and vulnerability assessment service is being procured. Bidders must be registered on the National Treasury’s Central Suppliers Database.
Always check the official documentDescription
The merSETA invites service providers to conduct ICT security penetration and vulnerability assessments. The project involves performing eight assessments over two years, including testing ten public or private applications. The service provider must deliver detailed findings and recommendations for each assessment. The work will be managed by the merSETA. Key requirements include a lead resource with at least ten years of experience in cyber security and specific professional certifications. Bidders must provide a standards-based methodology proposal and three signed reference letters regarding ICT risk and security.
What you need to qualify
- CSD registration — Registration on the Central Supplier Database — required to do business with government.
- Registered company — An active CIPC-registered company in good standing.
- Tax clearance — A valid SARS tax compliance status (PIN) showing your tax affairs are in order.
- Other registration — An industry registration the tender requires (e.g. PSIRA, NHBRC, a professional or trade licence).
Full requirements
- Registered on National Treasury Central Suppliers Database (CSD)
- Valid Tax Compliance status
- Lead resource must have 10+ years of experience
- Valid professional certification: CISA, CISM, or CSSP
- Valid company registration documents (CIPC, Partnership, or JV agreements)
Contact & how to apply
Name: Asisipho Matomane
Email: amatomane@merseta.org.za
Phone: 069-008-3764
How to apply: Applications must be submitted via email to quotations@merseta.org.za. The subject line of the email must clearly state the RFQ number (RFQ/ICT/26/27/020) and the tender description.
Related tenders
Assessment of PSETA's Information Security Systems.
The Public Service Sector Education and Training Authority (PSETA) seeks a service provider to assess its information security systems in alignment with the ISO 27001:2022 standard. The project includes evaluating current security controls, performing a gap analysis, and supporting ISO certification. It will be conducted in Pretoria over eight months. Bidders must submit a project plan, hourly rates, and proof of experience in security assessments. A compulsory briefing session is required, and the tender is valid for 120 days from the closing date.
Information Security and Cybersecurity Services for Postbank.
Postbank (SOC) Ltd seeks a qualified service provider for comprehensive Information Security and Cybersecurity services over three years. Responsibilities include securing infrastructure, 24/7 threat monitoring, incident response, and compliance with ISO 27001 and PCI DSS. All data must remain within South African borders. The submission deadline is 18 September 2026.
Service Provider for WAN Connectivity Services
The MICT SETA seeks a service provider for the implementation, support, and maintenance of WAN connectivity services across six sites in South Africa, including Midrand, Bloemfontein, and Cape Town. The project involves managing fibre connectivity, internet services, secure VPNs, and email filtering for 300 users over 60 months. Deliverables include next-generation firewalls, cloud backup for Microsoft 365, and 24/7 technical support. Bidders must provide a project implementation plan and risk management strategy.
Managed Cybersecurity Services Provider for NHBRC.
The National Home Builders Registration Council (NHBRC) seeks a Managed Cybersecurity Services Provider for a five-year contract. Services include 24/7/365 Security Operations Centre (SOC) operations, incident response, vulnerability management, penetration testing, and cyber awareness training. All SOC operations must occur within South Africa, covering the NHBRC head office and various offices nationwide. Deliverables include operational runbooks, risk reports, and maturity roadmaps. Bidders need five years of experience in enterprise-grade cybersecurity and must provide a detailed cost model. The tender uses the 80/20 preference point system.
Provision of ICT Equipment Maintenance for SANRAL.
The South African National Roads Agency (SANRAL) seeks tenders for break-fix services and maintenance of its ICT infrastructure at various locations in Gauteng over an 18-month period. Services include system health checks, firmware updates, and 24/7 support for critical issues, focusing on legacy infrastructure such as HPE servers and Veeam software. Bidders must provide certified technical experts and subcontract 30% of the work to Targeted Enterprises to ensure stable ICT operations until the National Data Centre rollout is complete.
Pre-employment security screening services for 36 months.
The Department of Land Reform and Rural Development seeks a service provider for a 36-month contract to deliver web-based pre-employment security screening services in Pretoria. Key tasks include biometric criminal record checks, identity and qualification verification, credit checks, and PSIRA verification. The provider must offer a system with link analysis, supply biometric fingerprint readers, and train 25 staff members. The system must comply with POPIA for secure data storage and maintain 99% availability. Responsibilities also include monthly management reporting, quarterly contract meetings, and delivering screening results within 5 to 7 working days.