Appointment of a Service Provider for Provision of Penetration Testing of Bankseta Information and Communication Technology Environment for a Period of Two (02) Years

BS/2025/RFB541

2025-12-12 11:00

Tender Closed on: 2026-01-27 11:00

https://tenderbulletins.co.za/tender-award/tender-award-appointment-of-a-service-provider-for-provision-of-penetration-testing-of-bankseta-information-and-communication-technology-environment-for-a-period-of-two-02-years/

Information and Communications Technology, IT Security Services and Solutions

Centurion, Gauteng

Banking Sector Education and Training Authority

Scroll down for tender details and to access the tender documents

Banking Sector Education and Training Authority Tenders

Account Functions

You will need an account login to View Tender Documents, Create a Business Listing on the site or to add your details to show your interest in joining a Joint Venture or working as subcontractor for this tender


  • Sign Up
Or Login Using
Please wait. Signing you in...
Or Login Using
Please wait. Signing you in...
Lost your password? Please enter your username or email address. You will receive a link to create a new password via email.
Tender Number: BS/2025/RFB541
Department: Banking Sector Education and Training Authority
Tender Type: Request for Bid(Open-Tender)
Province: Gauteng
Closing Date: Tuesday, 27 January 2026 - 11:00
Place where goods, works or services are required: Eco Origin Office Park, Block C2, 349 Witch-hazel Avenue, - Eco Park Estate, Highveld, - Centurion, - 0144
Special Conditions: N/A
ENQUIRIES:
Contact Person: EVA TABANE RATEMA
Email: [email protected]
Telephone number: 011-805-9661
FAX Number: N/A
BRIEFING SESSION:
Is there a briefing session?: Yes Is it compulsory? NO
Briefing Date and Time: Friday, 12 December 2025 - 11:00
Briefing Venue: [email protected]

This tender is also available from www.etenders.gov.za


Tender Summary

Objectives

The primary objective of this tender is to appoint a qualified service provider to conduct comprehensive penetration testing of the Bankseta Information and Communication Technology (ICT) environment over a period of two years. The testing aims to identify vulnerabilities across cloud infrastructure, network systems, web applications, physical security, wireless networks, and system configurations to enhance the security posture of Bankseta’s ICT environment.

Scope

The scope encompasses:

  • Penetration testing of Bankseta’s cloud infrastructure within Microsoft Azure and Microsoft 365 E5 services.
  • Assessment of network infrastructure including firewalls, routers, switches, access points, surveillance systems, and endpoints at Bankseta’s offices in Centurion, East London, and Polokwane.
  • Evaluation of web applications such as SharePoint and single sign-on systems.
  • Simulation of social engineering attacks to test staff awareness.
  • Physical security testing of access controls, surveillance, fingerprint, and card readers.
  • Wireless network security testing including Wi-Fi encryption and access controls.
  • System testing of operating systems on endpoints, surveillance servers, and network equipment.
  • Testing of third-party systems including ERP, HR, learner management, PABX, and internet services.
  • Reporting, remediation implementation, user awareness sessions, and warranty certificates over the two-year period.

Technical Requirements

The technical requirements include:

  • Assessment of security controls and vulnerabilities in cloud, network, web applications, wireless, physical, and system environments.
  • Provision of four detailed reports with recommendations, two annually.
  • Implementation of remediations totaling 160 hours over two years (80 hours per year).
  • Issuance of four assurance certificates confirming secure configurations post-remediation.
  • Conducting two user awareness sessions annually via Microsoft Teams.
  • Compliance with specified system specifications and infrastructure components listed in the tender.

Skills Requirements

The bidder must demonstrate:

  • Experience in penetration testing and security assessments of cloud, network, web, and physical systems.
  • Proven track record with reference letters from previous clients where penetration testing was successfully implemented.
  • Qualified personnel including:
    • A project manager with project management NQF Level 6 certification or higher, and experience in IT project management.
    • Team member no. 1 with at least NQF Level 4 or higher in Ethical Hacking and relevant certification.
    • Team member no. 2 with at least NQF Level 4 or higher in switching or networking and relevant certification.
  • Demonstrated experience in ethical hacking, switching, and networking.
  • Ability to provide open-source or proprietary tools with assurance of non-harmful impact on Bankseta’s systems.
  • Capacity to deliver reports, remediations, and user awareness sessions as specified.

Overall, the successful bidder must possess the technical expertise, personnel qualifications, and proven experience to deliver comprehensive penetration testing services aligned with the scope and technical requirements outlined in the tender.

This summary is AI generated. Download the tender documents for all the information.

How to Submit a Response / Quote to this Tender

The information needed for submitting your quote is in the description of the tender and the Tender Documents. You will also need documents and templates supplied by the entity that issued the tender, in order to supply the correct business and quote information.

To get the Tender Documents, click on the “Download Tender Documents” button below. This will take you to the Download page for this specific tender. To download the documents, you will need to create a Free Download account and then Login to this account. There is a Registration and Login form on the Download page, or above the tender description on this page. There are also Register and Login links at the top of all pages of this website.

Once you have the Tender Documents, complete them with your details and the quote details and submit to the entity or organisation that issued the tender. The details and method to submit are in the tender description and the tender documents.

Joint Ventures, Consortia and Subcontracting:

Most large tenders are composed of tasks in a number of different fields, and it is not always possible for a single company to cater for all of them, and therefore Joint Ventures and Consortia are formed to then submit a tender together.

Government tenders are also requiring the subcontracting of a percentage of the tender work, and the trouble is then finding Subcontractors to comply with the tender requirements

To assist companies with finding tender partners and subcontractors, you can now submit your contact details and company information on this page, so other interested parties can contact you for purposes of forming Joint Ventures and subcontracting

You will need to supply your details on every tender you are interested in tendering for. For this you need an active Business Listing - Register and Login at My Account to create a Business Listing

NOTE: This is not a tender application form, it is meant to facilitate the meeting of partners to form a Joint Venture or Subcontractor relationship for this tender only


To submit your details for this tender, you will need to Register an account - see the Registration form on this page or go to My Account

If you already registered, please login at My Account

You will also need to create a Business Listing in order to show your information here

Potential Subcontractor and Joint Venture Partners

To view a list of Businesses that match the Categories of this tender,
please Subscribe to a Paid Notification Plan

(If you are already a Paid Subscriber - not Trial, please Login to view this information on this tender)

Why not let us send tenders to your inbox?

from R120 per month