Sashastra Seema Bal Vulnerability and Penetration Testing Tender Shimla Himachal Pradesh 2025
Sashastra Seema Bal (ssb)
SHIMLA, HIMACHAL PRADESH
Bid Publish Date
06-Jan-2026, 1:14 pm
Bid End Date
17-Jan-2026, 1:00 pm
EMD
₹1,00,000
Value
₹54,00,000
Location
Progress
Quantity
1
Bid Type
Two Packet Bid
The Regional Pay And Accounts Office, under the Road Transport Highways division, seeks a comprehensive vulnerability and security assessment across multiple domains. The procurement covers Network, Web Application, Mobile, and IoT security testing, along with Security Infrastructure Review, OWASP Top 10 assessments, Secure Configuration Review, and Security Code Review. Estimated project value is ₹5,400,000 with an EMD of ₹100,000. The absence of BOQ items indicates a broad, integrative security audit scope rather than discrete line items. The contract appears to emphasize cross-domain security posture and governance, with emphasis on offensive and defensive testing disciplines. Bidder must align with this multi-domain security audit requirement and deliver actionable remediation recommendations. Location details are not disclosed in the tender data, signaling a nationwide or centralized procurement approach under the Regional Pay And Accounts Office. The tender’s distinctive feature is its breadth across IT infrastructure and applications, demanding a cohesive security assurance approach rather than isolated testing.
Vulnerability and Penetration Testing across Network, Web Application, Mobile, IoT
OWASP Top 10 based application security audit
Secure Configuration Review for devices and operating systems
Security Code Review for applications in scope
Integrated security reporting with remediation recommendations
No discrete BOQ items; holistic security assessment scope
EMD of ₹100,000 required; bid security to be furnished as per terms
Contract quantity/duration adjustable up to 25% at issue and post-issuance
No BOQ items; expect consolidated security audit deliverables and reporting
Not explicitly specified; bidders should align with standard government payment timelines post-delivery of deliverables
Not specified; anticipate milestones for initial assessment, interim findings, and final remediation report
Not specified; bidders should seek clarity on SLAs and LD provisions in final contract
Experience in multi-domain security testing (network, app, mobile, IoT)
Proven ability to perform OWASP Top 10 assessments and secure configuration reviews
Demonstrated reporting maturity with actionable remediation guidance
Sashastra Seema Bal (ssb)
SHIMLA, HIMACHAL PRADESH
Armoured Vehicles Nigam Limited
THANE, MAHARASHTRA
Central University Of Haryana
MAHENDRAGARH, HARYANA
Directorate General Of Quality Assurance ( Dgqa)
N/a
CENTRAL DELHI, DELHI
Tender Results
Loading results...
Discover companies most likely to bid on this tender
GST registration certificate
Permanent Account Number (PAN) card
Experience certificates demonstrating cross-domain security testing
Financial statements or turnover evidence for last financial year
EMD/submission security deposit receipt (₹100,000)
Technical bid documents detailing testing methodologies and tools
Authorization letters from OEMs for testing tools (if applicable)
Key insights about DELHI tender market
Bidders must submit GST, PAN, experience certificates, and financials with the bid, plus EMD of ₹100,000. The scope covers network, web, mobile, and IoT testing, OWASP Top 10 audits, and secure configuration reviews. Ensure documentation includes testing methodologies and tool licenses if required.
Required documents include GST registration, PAN, recent turnover statements, experience certificates for multi-domain testing, EMD receipt of ₹100,000, technical bid detailing tools and methods, and OEM authorizations for tools if applicable. Ensure all documents are current and verifiable.
The tender requires OWASP Top 10 based assessment across web and mobile applications, with risk-ranked remediation plans. Use OWASP ASVS where applicable and provide evidence of formal testing procedures, severity ratings, and remediation timelines in the final report.
The exact submission deadline is not provided in the data; bidders should monitor the tender portal for notifications and ensure readiness with all documents, EMD, and technical proposal to avoid last-minute issues when the portal opens.
Payment terms are not explicitly stated; bidders should seek clarity on milestone-based payments post-delivery of interim findings and final remediation report, aligning with standard government procurement processes and certified acceptance.
The EMD is ₹100,000. Submit via online payment or as demanded by the procuring authority, accompanied by bid security documents. Ensure EMD is valid through the evaluation period and contract award date.
Deliverables include a comprehensive security assessment report covering Network, Web, Mobile, and IoT, OWASP Top 10 findings, Secure Configuration Review, Security Code Review, and a remediation plan with prioritized Risk Ratings and timelines.
The procurement is issued by Regional Pay And Accounts Office under the Road Transport Highways department. The scope targets multi-domain vulnerability testing and secure configuration reviews across IT and OT-like environments.
Fatehpur District Central Cooperative Bank Ltd.
📍 FATEHPUR, UTTAR PRADESH
Indian Council Of Agricultural Research (icar)
📍 CENTRAL DELHI, DELHI
Tata Memorial Centre
📍 MUMBAI, MAHARASHTRA
Directorate General Of Quality Assurance ( Dgqa)
📍 HYDERABAD, TELANGANA
Controller General Of Defence Accounts
Sign up now to access all documents
Main Document
OTHER
SCOPE_OF_WORK
GEM_GENERAL_TERMS_AND_CONDITIONS