Vulnerability and Penetration Testing - Cyber Security Audit; Security & Compliance Audit Report(Co
Directorate General Of Quality Assurance ( Dgqa)
KANCHIPURAM, TAMIL NADU
Progress
Quantity
1
Bid Type
Two Packet Bid
Mod Sectt Establishment of the Department Of Defence invites bids for Vulnerability and Penetration Testing - Web Application services, including application security audit (OWASP Top 10), Malware Analysis, and Pre-hosting assessment of applications. The scope covers ethical hacking, vulnerability addressing, and a plug-in solution recommendation. The contract contemplates service provision with on-site support, and a potential quantity/duration adjustment up to 25% at the time of issue and post-issue. The bidder must demonstrate the ability to operate within the consignee’s state through an accredited service presence. No BOQ items are listed, indicating a broad security testing framework rather than commodity goods.
Vulnerability and Penetration Testing scope for web applications with OWASP Top 10 alignment
Malware analysis and pre-hosting assessment services
Plug-in solution recommendation to mitigate findings
On-site service capability in consignee state with documented escalation matrix
Joint liability with subcontractors and no unauthorized assignment
25% quantity/duration adjustment allowed; acceptance required
No subcontracting without prior written consent from buyer
Bidder must not be in liquidation or bankruptcy; provide undertaking
Mandatory certificates/documents must be uploaded as specified
Office of service provider must be located in the consignee state
Escalation matrix for service support required
The tender permits quantity/duration variation up to 25% at contract issue and thereafter; payment terms not explicitly defined in data provided.
No explicit delivery timeline; service delivery is contingent on on-site support and project milestones defined in ATC.
No LD details provided in data; penalties likely governed by ATC and supplier agreement.
Evidence of non-liquidation/bankruptcy and financial viability
Ability to provide on-site security testing services in consignee state
Compliance with ATC/corrigendum certificates and required OEM authorizations
Main Document
SCOPE_OF_WORK
ATC
GEM_GENERAL_TERMS_AND_CONDITIONS
Directorate General Of Quality Assurance ( Dgqa)
KANCHIPURAM, TAMIL NADU
Sashastra Seema Bal (ssb)
DURG, CHHATTISGARH
Directorate General Of Quality Assurance ( Dgqa)
HYDERABAD, TELANGANA
Directorate General Of Quality Assurance ( Dgqa)
MUMBAI, MAHARASHTRA
Centre For Development Of Advanced Computing (c-dac)
PUNE, MAHARASHTRA
Tender Results
Loading results...
Discover companies most likely to bid on this tender
GST registration certificate
Permanent Account Number (PAN) card
Experience certificates of similar security testing engagements
Financial statements demonstrating financial stability
EMD/Security deposit documentation (if applicable per ATC)
Technical bid documents and method statements
OEM/partners authorizations (if required)
Escalation matrix and service support contact details
Proof of local service office in the consignee state
Key insights about DELHI tender market
Bidders must meet eligibility criteria including on-site service capability in the consignee state, submission of GST, PAN, and experience certificates, plus OEM authorizations if required. Provide a detailed method statement for OWASP Top 10 aligned testing and malware analysis, with an escalation matrix and compliant documentation in the bid submission.
Required documents include GST certificate, PAN, company financial statements, prior security testing experience certificates, OEM authorizations, technical bid, and an escalation matrix. Upload certification proof referenced in ATC and Corrigendum; ensure subcontractor approvals are documented if applicable.
Tenders expect OWASP Top 10 compliant testing with a formal vulnerability assessment and penetration testing delivered to mitigate web app risks. Provide methodology, risk ratings, and remediation recommendations aligned to industry best practices and security controls.
An escalation matrix with telephone contacts must be submitted as part of the service support proposal. It ensures prompt issue resolution; include multiple levels (vendor, OEM, regional) with response times and hours of operation.
The contractor must maintain an office or authorized service facility within the consignee state. Provide proof of address, local staff, and a dedicated point of contact for on-site security testing and post-deployment support.
The buyer may modify contract quantity/duration by up to 25%, requiring the bidder to adjust project scope and pricing accordingly. Acceptance of revised terms is mandatory for award continuation; ensure pricing reflects potential variation.
N/a
📍 CHHINDWARA, MADHYA PRADESH
National Security Guard (nsg)
📍 GURGAON, HARYANA
Tata Memorial Centre
📍 MUMBAI, MAHARASHTRA
Director General Telecom Hq
📍 ERNAKULAM, KERALA
Directorate General Of Quality Assurance ( Dgqa)
📍 KANCHIPURAM, TAMIL NADU
Sign up now to access all documents
Main Document
SCOPE_OF_WORK
ATC
GEM_GENERAL_TERMS_AND_CONDITIONS