GEM

Central University Of Haryana Vulnerability Testing Tender Web Application Security Audit 2025

Bid Publish Date

24-Nov-2025, 12:14 pm

Bid End Date

04-Dec-2025, 1:00 pm

Value

₹1,50,000

Progress

Issue24-Nov-2025, 12:14 pm
AwardPending
Explore all 4 tabs to view complete tender details

Quantity

1

Bid Type

Two Packet Bid

Categories 5

Tender Overview

The Central University Of Haryana, Department Of Higher Education, seeks a service provider for vulnerability assessment and penetration testing of web applications, plus security audits including OWASP Top 10, secure configuration reviews for devices/OS, and vulnerability addressing. Estimated value is ₹150,000 with no BOQ items listed. Location is Haryana, and the procurement focuses on vulnerability testing, application security, and plug-in recommendations. The scope emphasizes audit quality, adherence to established security standards, and actionable remediation guidance. The absence of detailed specifications suggests a flexible approach to method and deliverables, with emphasis on comprehensive risk reporting and practical security enhancements.

  • Organization: Central University Of Haryana
  • Category: Vulnerability and Penetration Testing - Web Application; Security Infrastructure Review; OWASP Top 10
  • Estimated value: ₹150,000
  • Location: Haryana, India
  • Key differentiator: emphasis on OWASP Top 10, secure configuration reviews, and plug-in solution recommendations
  • Unique aspect: minimal BOQ information; focus on security assessment scope and remediation guidance

Technical Specifications & Requirements

  • Product/Service: Vulnerability Assessment, Penetration Testing (Web Applications), Security Infrastructure Review, Application Security Audit, and Plug-in solution recommendations
  • Scope elements: OWASP Top 10 assessment, secure configuration review for devices/OS, vulnerability addressing plan
  • Data points: No specific hardware, software, or platform details provided; contractor must propose methodology, tools alignment, and deliverables
  • Standards expectation: Not explicitly listed; bidders should infer best-practice security testing frameworks and produce remediation recommendations
  • Estimated contract value: ₹150,000
  • Delivery context: Post-engagement reporting with actionable mitigation steps

Terms, Conditions & Eligibility

  • EMD: Not specified in data; bidders should verify in bid documents
  • Quantity/Duration: Contract quantity/duration may adjust up to 25% at issue or post-issuance
  • Excess charges: Optional addition up to a declared percentage; requires supporting documentation
  • Certification requirements: Upload of certificates/documents as per Bid document/ATC
  • Mandatory ATC: Compliance with uploaded ATC and corrigenda
  • Documentation: GSTIN, PAN, experience certificates, financials, technical bids, OEM authorizations where required
  • Penalties/warranty: Not specified here; check tender terms for LD or warranty clauses

Key Specifications

    • Product/Service: Vulnerability Assessment, Penetration Testing (Web Applications), Security Infrastructure Review, Application Security Audit (OWASP Top 10), Secure Configuration Review (Devices/OS)
    • Scope: Identify vulnerabilities, address remediation, and propose a plug-in solution
    • Capabilities: Demonstrated experience in OWASP Top 10 remediation, secure configuration reviews, and vulnerability addressing
    • Deliverables: Comprehensive risk report, remediation plan, and plug-in recommendation with implementation steps
    • Standards/Compliance: Align with general industry best practices for web security testing; specific standards not listed in tender data

Terms & Conditions

  • Emergency/Variation: Contract quantity or duration may vary up to 25% at contract issue and later

  • Excess settlement: Additional charges allowed up to a declared percentage with supporting documents

  • Mandatory documents: Upload required certificates/documents as per bid terms and ATC

Important Clauses

Payment Terms

Not explicitly provided; bidders should refer to bid documents for payment milestones and schedules

Delivery Schedule

No explicit delivery timeline; terms indicate post-award deliverables in a standard security assessment engagement

Penalties/Liquidated Damages

Not specified in data; check ATC for LD/penalty structures and performance bonds

Bidder Eligibility

  • Experience in web application security assessment and OWASP Top 10 remediation

  • Ability to provide vulnerability addressing plans and plug-in solution recommendations

  • Compliance with standard bid submission requirements (GST, PAN, financials, technical bid)

Past Similar Tenders (Historical Results)

5 found

Vulnerability and Penetration Testing

National Security Guard (nsg)

GURGAON, HARYANA

Posted: 2 September 2025
Closed: 23 September 2025
GEM

Vulnerability and Penetration Testing

Animal Welfare Board Of India

FARIDABAD, HARYANA

Posted: 19 July 2025
Closed: 31 July 2025
GEM

Vulnerability and Penetration Testing,Vulnerability and Penetration Testing,Vulnerability and Penet

Centre For Development Of Advanced Computing (c-dac)

Posted: 5 December 2024
Closed: 16 December 2024
GEM

Cyber Security Audit - Web Application Security Audit

Thdc India Limited

Posted: 26 November 2024
Closed: 10 December 2024
GEM

Vulnerability and Penetration Testing

Hindustan Aeronautics Limited (hal)

BANGALORE, KARNATAKA

Posted: 10 January 2025
Closed: 17 January 2025
GEM

🤖 AI-Powered Bidder Prediction

Discover companies most likely to bid on this tender

Live AI
Historical Data

Required Documents

1

GST registration certificate

2

Permanent Account Number (PAN) card

3

Experience certificates for similar web security projects

4

Financial statements (audited, if available)

5

EMD/Security deposit documents (as applicable in bid documents)

6

Technical bid documents showing methodology and tools

7

OEM authorizations or certificates if required by the bidder's solution

8

Any certificates/permissions specified in ATC or corrigendum

Frequently Asked Questions

Key insights about HARYANA tender market

How to bid for the web security tender in Haryana 2025

Bidders should submit the technical bid with a clear methodology for vulnerability assessment, OWASP Top 10 coverage, and remediation plans. Include GST, PAN, experience certificates, financials, OEM authorizations if required, and any ATC-specific documents. Ensure compliance with the 25% variation clause if applicable.

What documents are required for this vulnerability testing tender in Haryana

Required documents include GST registration, PAN, past project experience certificates for web security, audited financial statements, technical bid detailing tools/methodology, and any OEM authorizations. ATC and corrigenda must be uploaded; ensure all certificates are valid and current.

What are the technical requirements for OWASP Top 10 security audit

The bidder must perform a comprehensive OWASP Top 10 assessment, identify vulnerabilities, and provide remediation guidance. Deliverables should include a risk report, prioritized fix plan, and a plug-in solution recommendation with implementation steps and timelines.

What is the estimated contract value for the Central University of Haryana tender

The tender has an estimated value of ₹150,000. Vendors should account for security assessment labor, reporting, and remediation recommendations within this budget while ensuring compliance with all ATC requirements.

When is the variation clause applicable for contract quantity or duration

The buyer can adjust contract quantity or duration up to 25% at the time of contract issue, and again up to 25% after issue. Bidders must accept revised quantity or duration and adjust pricing accordingly.

What are the mandatory submission requirements for certificates

Bidders must upload all required certificates/documents cited in the Bid Document, ATC, and corrigenda. This includes any security certifications, vendor authorizations, and compliance certificates relevant to vulnerability testing and plug-in recommendations.

What are the payment terms for the security testing services contract

Payment terms are described in the bid documents; however, typical terms include milestone-based payments upon delivery of security assessment reports, remediation plans, and acceptance by the procuring organization, subject to submission of all required documents and invoices.

What standards or certifications are required for this tender in Haryana

The tender references general security testing practices and OWASP Top 10; explicit standards are not listed in the data. Bidders should reference IS/ISO-based best practices and provide any relevant certifications (if specified in ATC) to demonstrate capability.

Similar Tenders

4 found

Cyber Security Audit - Infrastructure Audit, , Conduct IT Audit and Vulnerability Assessment Penet

Kiocl Limited

📍 BANGALORE, KARNATAKA

EMD: ₹30,000
⏰ Deadline: 2 weeks left
🛒 Type: Service
View GEM
Urgent

Uttarakhand Finance Department Vulnerability & Penetration Testing Tender 2025 - Web & Mobile Apps ATC Compliance

N/a

📍 DEHRADUN, UTTARAKHAND

⏰ Deadline: 3 days left
🛒 Type: Service
View GEM
Urgent

Vulnerability and Penetration Testing

Gujarat Informatics Limited (gil)

EMD: ₹3.0 L
⏰ Deadline: 4 days left
🛒 Type: Service
View GEM

Cyber Security Audit - Infrastructure Audit, Operations, Management Process and Control Audit, SLA

N/a

📍 CENTRAL DELHI, DELHI

EMD: ₹25,000
Est: ₹10.0 L
⏰ Deadline: 2 weeks left
🛒 Type: Service
View GEM