Vulnerability and Penetration Testing
National Security Guard (nsg)
GURGAON, HARYANA
Bid Publish Date
24-Nov-2025, 12:14 pm
Bid End Date
04-Dec-2025, 1:00 pm
Value
₹1,50,000
Location
Progress
Quantity
1
Bid Type
Two Packet Bid
The Central University Of Haryana, Department Of Higher Education, seeks a service provider for vulnerability assessment and penetration testing of web applications, plus security audits including OWASP Top 10, secure configuration reviews for devices/OS, and vulnerability addressing. Estimated value is ₹150,000 with no BOQ items listed. Location is Haryana, and the procurement focuses on vulnerability testing, application security, and plug-in recommendations. The scope emphasizes audit quality, adherence to established security standards, and actionable remediation guidance. The absence of detailed specifications suggests a flexible approach to method and deliverables, with emphasis on comprehensive risk reporting and practical security enhancements.
Emergency/Variation: Contract quantity or duration may vary up to 25% at contract issue and later
Excess settlement: Additional charges allowed up to a declared percentage with supporting documents
Mandatory documents: Upload required certificates/documents as per bid terms and ATC
Not explicitly provided; bidders should refer to bid documents for payment milestones and schedules
No explicit delivery timeline; terms indicate post-award deliverables in a standard security assessment engagement
Not specified in data; check ATC for LD/penalty structures and performance bonds
Experience in web application security assessment and OWASP Top 10 remediation
Ability to provide vulnerability addressing plans and plug-in solution recommendations
Compliance with standard bid submission requirements (GST, PAN, financials, technical bid)
National Security Guard (nsg)
GURGAON, HARYANA
Animal Welfare Board Of India
FARIDABAD, HARYANA
Centre For Development Of Advanced Computing (c-dac)
Thdc India Limited
Hindustan Aeronautics Limited (hal)
BANGALORE, KARNATAKA
Tender Results
Loading results...
Discover companies most likely to bid on this tender
GST registration certificate
Permanent Account Number (PAN) card
Experience certificates for similar web security projects
Financial statements (audited, if available)
EMD/Security deposit documents (as applicable in bid documents)
Technical bid documents showing methodology and tools
OEM authorizations or certificates if required by the bidder's solution
Any certificates/permissions specified in ATC or corrigendum
Key insights about HARYANA tender market
Bidders should submit the technical bid with a clear methodology for vulnerability assessment, OWASP Top 10 coverage, and remediation plans. Include GST, PAN, experience certificates, financials, OEM authorizations if required, and any ATC-specific documents. Ensure compliance with the 25% variation clause if applicable.
Required documents include GST registration, PAN, past project experience certificates for web security, audited financial statements, technical bid detailing tools/methodology, and any OEM authorizations. ATC and corrigenda must be uploaded; ensure all certificates are valid and current.
The bidder must perform a comprehensive OWASP Top 10 assessment, identify vulnerabilities, and provide remediation guidance. Deliverables should include a risk report, prioritized fix plan, and a plug-in solution recommendation with implementation steps and timelines.
The tender has an estimated value of ₹150,000. Vendors should account for security assessment labor, reporting, and remediation recommendations within this budget while ensuring compliance with all ATC requirements.
The buyer can adjust contract quantity or duration up to 25% at the time of contract issue, and again up to 25% after issue. Bidders must accept revised quantity or duration and adjust pricing accordingly.
Bidders must upload all required certificates/documents cited in the Bid Document, ATC, and corrigenda. This includes any security certifications, vendor authorizations, and compliance certificates relevant to vulnerability testing and plug-in recommendations.
Payment terms are described in the bid documents; however, typical terms include milestone-based payments upon delivery of security assessment reports, remediation plans, and acceptance by the procuring organization, subject to submission of all required documents and invoices.
The tender references general security testing practices and OWASP Top 10; explicit standards are not listed in the data. Bidders should reference IS/ISO-based best practices and provide any relevant certifications (if specified in ATC) to demonstrate capability.
Kiocl Limited
📍 BANGALORE, KARNATAKA
N/a
📍 DEHRADUN, UTTARAKHAND
Gujarat Informatics Limited (gil)
N/a
📍 CENTRAL DELHI, DELHI
Access all tender documents at no cost
Main Document
TECHNICAL
SCOPE_OF_WORK
ATC
GEM_GENERAL_TERMS_AND_CONDITIONS
Main Document
TECHNICAL
SCOPE_OF_WORK
ATC
GEM_GENERAL_TERMS_AND_CONDITIONS