Vulnerability and Penetration Testing
Bharat Electronics Limited (bel)
GHAZIABAD, UTTAR PRADESH
Bid Publish Date
18-Nov-2025, 3:19 pm
Bid End Date
01-Dec-2025, 4:00 pm
Bid Opening Date
01-Dec-2025, 4:30 pm
Location
Progress
Quantity
1
Bid Type
Two Packet Bid
The Uttarakhand Finance Department invites a Vulnerability and Penetration Testing (VAPT) bid covering Web Applications and Mobile Applications as per Attributable Terms and Conditions (ATC). The procurement scope is described under ATC and Scope with no explicit BOQ items or quantities published. The contract includes a flexible 25% adjustment window for quantity or duration at the contract issue stage, with a follow-on allowance of up to 25% post-issuance. This tender targets qualified security testing vendors capable of dynamic and static assessments, risk assessment, and remediation advisory under government procurement norms in Uttarakhand. A clear differentiator is the formal ATC attachment governing scope and invoicing allowances. Unique aspects include the optional excess settlement mechanism and the explicit quantity/duration adjustment cap.
Product/Service: Vulnerability and Penetration Testing for Web Applications and Mobile Applications
Scope reference: ATC document attached to tender (not provided in data)
Estimated value: Not disclosed in available data; rely on ATC for value bands
Standards/Certifications: Specific standards not listed in data; verify ATC for required certifications
Testing outputs: Security assessment report, remediation guidance, risk rating, and traceable results
Invoicing: Excess settlement with supporting documents; percentage cap to be defined in ATC
25% quantity/duration adjustment allowed at contract issue
Excess settlement invoicing with mandatory supporting documents
Submit ATC-compliant technical bid with standard government documents
Excess charges allowed up to a defined percentage; declare applicability during invoice creation with supporting documents
Delivery milestones to be defined in ATC; no explicit dates in available data
Not specified in current data; review ATC for LD provisions
Proven experience in executing Vulnerability and Penetration Testing for web and mobile apps
Ability to comply with government procurement ATC terms and conditions
Registered GST, valid PAN, and financial statements (as required)
Bharat Electronics Limited (bel)
GHAZIABAD, UTTAR PRADESH
Govind Ballabh Pant (g.b. Pant) Institute Of Himalayan Environment And Development (gbpihed)
North Eastern Electric Power Corporation Limited
EAST KHASI HILLS, MEGHALAYA
Grid Controller Of India Limited
Indian Army
WEST DELHI, DELHI
Tender Results
Loading results...
Discover companies most likely to bid on this tender
GST certificate
PAN card
Experience certificates for similar VAPT projects
Financial statements (audited, if available)
EMD/ Security deposit documentation as per ATC
Technical bid document aligned to ATC requirements
OEM authorizations or proof of capability for testing tools (if required by ATC)
Key insights about UTTARAKHAND tender market
Bidders should submit ATC-aligned technical bids, provide GST and PAN, supply experience certificates for web/mobile VAPT, and attach EMD documentation as per ATC. Ensure you understand the 25% quantity/duration flex and the excess settlement invoicing rule with required supporting documents.
Submit GST certificate, PAN card, recent experience certificates for similar VAPT projects, audited financial statements if available, security/testing tool capabilities, OEM authorizations if applicable, and the ATC-compliant technical bid reflecting scope and invoicing rules.
Testing scope includes vulnerability assessment and penetration testing for web and mobile applications as per ATC. Deliverables should include a detailed security assessment report, risk ratings, remediation guidance, and a traceable set of findings aligned to the ATC requirements.
The available data does not publish explicit dates; bidders should monitor ATC attachments for deadlines. Payment terms follow the excess settlement policy; any extra charges require declaration and supporting documents during invoice generation.
EMD requirements are not specified in the data; bidders must check ATC for exact EMD amount, mode of payment, and submission deadlines to qualify for bid submission.
The tender data does not list explicit standards; bidders should refer to the uploaded ATC document, which may specify required certifications and tool capabilities for web and mobile application security testing.
The contract allows a ±25% adjustment in quantity or duration at issue and a further ±25% after issuance. Vendors must accept revised scope and align invoices with the adjusted quantity, ensuring documentation supports any changes.
Include approach to web/mobile VAPT, testing methodologies, toolset details, team CVs, past project summaries, compliance with ATC terms, and clear mapping to risk remediation outputs, plus all required statutory documents.
Tata Memorial Centre
📍 MUMBAI, MAHARASHTRA
Indian Bank
📍 CHENNAI, TAMIL NADU
Export Import Bank Of India
📍 MUMBAI, MAHARASHTRA
Institute For Plasma Research
N/a
Access all tender documents at no cost
Main Document
SCOPE_OF_WORK
ATC
GEM_GENERAL_TERMS_AND_CONDITIONS
Main Document
SCOPE_OF_WORK
ATC
GEM_GENERAL_TERMS_AND_CONDITIONS