Publication / RFP date
Tender/RFP published on 07 August 2026 (GeM bid dated 07-08-2026; RFP Date 07/08/2026).
- Reference: GEM/2026/B/7890556; RFP Tender No. 000100/HO IT/RFP/554/2025-2026.
Loading…
Cyber Security Audit - 1
United India Insurance Company Ltd · Chennai, Tamil Nadu9724992
Written by TenderKart AI from the documents published when it was generated. Check the tender for later corrigenda before you bid.
7 Aug 2026
11 Sept 2026
₹8 L
All important dates as they stand after corrigenda: publication, pre-bid/clarification deadline, bid submission deadline, bid opening, and bid validity period.
Tender/RFP published on 07 August 2026 (GeM bid dated 07-08-2026; RFP Date 07/08/2026).
Last date for submitting pre-bid queries is 14th August, 2026, by email only to [email protected] in the Annexure-11 Excel format.
Pre-bid meeting is scheduled on 18th August, 2026; UIIC may conduct it virtually by video conference.
Last date/time for online bid submission on GeM is 28-08-2026 21:00:00 (RFP: 28th August, 2026 till 09:00 p.m.).
GeM Bid Opening Date/Time is 28-08-2026 21:30:00; RFP separately states Opening of Technical Bid on 31st August, 2026 @ 12:00 p.m.
Bid offer validity is 180 days from the bid end/last date of submission.
Contract/appointment is for Three years / 36 months; LOA acceptance within 15 days; Performance Security within 20 days of Notification of Appointment, valid 39 months from LOA.
Tender value or estimated cost, EMD/bid security (amount, acceptable forms, validity), tender document fees, performance security, and key payment terms.
No numeric estimated bid value/tender value is printed in the available GeM bid fields or RFP; GeM only states that any Estimated Bid Value is for EMD/eligibility guidance and not for pricing reasonableness.
EMD is Rs.8,00,000 (Rupees Eight Lakhs only); preferred mode Bank Guarantee (Annexure 7) or NEFT; GeM also allows surety bond; BG validity 6 months from bid submission cut-off; EMD carries no interest.
No tender fee is applicable.
Performance security / ePBG is 3% of total contract value, to be furnished within 20 days of Notification of Appointment as irrevocable BG/DD from Nationalized/Scheduled Bank; validity 39 months from LOA (GeM ePBG duration 39 months).
Payments are activity-linked per RFP 4.27 (mostly 100% on final signed report; VAPT/External VA&PT 50% initial + 50% revalidation); GeM requires payment within 45 days of SDAC and online bill submission; currency INR; prices exclusive of GST.
Every pass/fail eligibility and qualification requirement: experience and past performance, turnover/net worth, registrations and certifications, consortium/JV rules, and debarment or blacklisting conditions.
Bidder must be a Company / Partnership Firm / LLP registered in India for more than 5 years as on RFP date (other modes not acceptable), with registered office in India, valid GST and PAN, and statutory tax registrations; in operation last five years per definitions.
Average annual turnover from India cyber security services operations not less than 4 Crores in each of FY 2023-24, 2024-25, 2025-26 (Start-ups/MSEs: minimum average annual turnover 2 crores for that period); positive net worth in all 3 FYs; profit in at least 2 of last 3 FYs.
Bidder must be empaneled with CERT-In for Information Security Audit services as on RFP publication date; certificate must remain valid when signing Initial/Final reports for specified audits.
Bidder must bid individually and not as a consortium, and must have a project office in Chennai (self-declarations 12D and 12E).
Bidder must not be blacklisted by Govt/PSU/etc. as on RFP date; not from a land-border sharing country unless registered with Competent Authority; must not be providing Information & Cyber Forensic services to UIIC as on RFP date; must meet IRDAI Annexure-IV audit firm eligibility; and must comply with CVC tender guidelines.
Technical bid scored on Annexure-14 (100 marks max); minimum 60 marks to open commercial bid; evaluation is QCBS with Technical:Financial weightage 70:30.
Deployed resources must be permanent employees (not part-time/outsourced), drawn from Annexure-14 profiles (or equivalent), qualified with relevant certifications, and use only authorized licensed tools.
What is being procured: the work, supplies or services, deliverables and quantities, locations, phases, completion or delivery timelines, applicable standards, and notable exclusions.
Appointment of an independent CERT-In empaneled IS Auditor for Comprehensive Information and Cyber Security Assurance Audit for UIIC for three years, aligned to IRDAI guidelines dated 06th April, 2026 and amendments.
In-scope offices/centres: Head Office, Data Centre, DR Site and NDR Site; indicative inventory includes internal apps 40±10, external apps/APIs 40±10, servers 200±30, auth servers 4, proxy 1, network devices 20, desktops 1000±200, laptops 150±30.
Nine commercial line items over the contract: annual Comprehensive VAPT (3), IRDAI Compliance Audit (3), IS Assurance Audit (3), External Application VA&PT (3), Red Team (3), Training (6 = 4 online + 2 offline), Table Top (3), Phishing (6), and Ad-hoc VAPT man-day unit (1 quoted unit; PO on need).
Testing/standards reference OWASP Top 10, OWASP ASVS, NIST CSF, SANS controls, OWASP Testing Guide, MITRE ATT&CK; only authorized licensed tools; reports in DOC/PDF/XLS/PPTX/hard copy as required.
The complete checklist of documents to submit — mandatory vs conditional, with any prescribed formats, proformas or annexures — plus how to submit: portal and mode, envelope/cover structure, digital signature requirements, signing and attestation rules, and physical originals with their deadline.
Single-stage online submission on GeM Portal only (two-stage opening: Technical then Commercial); no other mode accepted; hard copies only if demanded or clarification sought.
Technical packet: Annexures 1–14 and 16; Commercial packet: Annexure-15 BOM/TCO (unmasked) plus masked BOM replica in technical bid with ‘XX’ for prices; documents page-numbered; signed by authorized signatory under Power of Attorney.
Pre-Contract Integrity Pact must be submitted in 2 (Two) copies on ₹100 stamp paper (Annexure 9); signing is preliminary eligibility—refusal disqualifies.
Every corrigendum/addendum in order — what changed (original vs amended value), its impact, and the action for the bidder — ending with the values that finally apply.
No corrigendum or addendum documents are present in the tender pack; original GeM bid (07-08-2026) and RFP dated 07/08/2026 values currently apply.
Final operative timeline/financials as published: bid end 28-08-2026 21:00; GeM opening 28-08-2026 21:30 (RFP technical opening text 31-08-2026 12:00 p.m.—see contradictions); validity 180 days; EMD ₹8,00,000; ePBG/PBG 3% for 39 months; contract 3 years; QCBS 70:30 with technical cutoff 60.
Genuine conflicts within and across the documents (original vs corrigenda, clause vs annexure, tender document vs BOQ): both sides with citations, and which value prevails.
GeM Bid Opening is 28-08-2026 21:30:00, while RFP Schedule states Opening of Technical Bid on 31st August, 2026 @ 12:00 p.m.
GeM Bid Details field shows “Evaluation Method: Total value wise evaluation”, but the same GeM document and RFP mandate QCBS 70:30 with technical cutoff 60.
Scope summary table lists Regular Training frequency as “Quarterly”, but Section 2.6 requires only 4 virtual + 2 on-site trainings and BOM/Excel quantities are 6 units for the contract.
RFP specifies Bank Guarantee (preferred) or NEFT only, while GeM also states EMD shall be accepted as a surety bond.
GeM sets seller payment within 45 days of SDAC and online bills, while RFP 4.27 ties payment percentages to submission of signed initial/final/revalidation reports per activity.
Only critical, tender-specific pre-bid queries that could materially change bid/no-bid, pricing, eligibility or contractual risk. Skip generic or obvious questions the documents already answer clearly.
Please confirm whether technical bids open on GeM at 28-08-2026 21:30 or on 31-08-2026 12:00 p.m. as in RFP 1.5, and publish a corrigendum aligning both.
Please confirm the exact QCBS composite formula (normalization of commercial score) and that award is not pure L1 despite GeM “Total value wise evaluation” wording.
Please clarify whether Regular Training is quarterly each year or limited to 6 sessions (4 online + 2 offline) over the 3-year contract as per Section 2.6 and BOM quantity 6.
Section 2.9 asks for man-day rate and also unit price per API and Web service/URL, but Annexure-15/Excel has only one man-day line with quantity 1—please confirm what must be quoted and how call-offs will be ordered/paid.
Annexure 9 requires 2 stamp-paper copies of Integrity Pact, while bid submission is GeM-only—please confirm whether originals must be couriered, to which address, and by what deadline relative to bid end.
Please confirm whether cyber-security turnover must be ≥ ₹4 Cr in each of FY23-24/24-25/25-26 (RFP 13C wording) or as a three-year average (GeM average turnover phrasing), and whether FY 2025-26 audited figures are mandatory if bid is in Aug 2026 before audit finalization.
Please share city/addresses (or at least cities) of Data Centre, DR and NDR and expected onsite duration per exercise, since commercials must include all travel/stay with no reimbursables.
Commercial, legal and execution risks a bidder should weigh: liquidated damages and penalties, unusual or one-sided clauses, tight timelines, and payment or security risks.
LD of 1% of each SOW/year PO amount per week (or part) of delay, capped at 5%, then UIIC may terminate; invalid CERT-In at report signing attracts additional 5% LD and payment withholding/report rejection at bidder cost.
Many exercises must finish within 30–45 days of UIIC intimation, with revalidation in 30 days, while prices are firm for 36 months with no out-of-pocket reimbursement and bidder bears travel/stay.
UIIC may terminate for default/unsatisfactory progress (30-day cure), insolvency without compensation, convenience, or cancel and recover damages; failure to furnish PBG can annul award and blacklist for 2 years.
Forensic-service conflict with UIIC is an absolute bar; successful auditor is barred from UIIC cyber-forensic tenders during contract; resources must be permanent employees from submitted profiles.
No advance; payments are back-ended to signed reports/training completion and GeM 45-day post-SDAC cycle; CERT-In issues can freeze payment entirely for the activity.
The inviting authority and relevant contacts: office, person, designation, address, phone and email — and which address receives physical submissions, if any.
United India Insurance Company Limited (UIIC), IT Department, Head Office — United India Bhavan, No. 24, Whites Road, Royapettah, Chennai – 600 014; Ministry of Finance / Department of Financial Services; GeM office name North.
Primary RFP email for communication/queries/clarifications: [email protected]; pre-bid authorization details also to this email at least two days before meeting.
GeM Buyer Email: [email protected]; HOD grievance email: [email protected]; EMD/PBG Beneficiary Chief Manager Suresh Kumar M K, UNITED INDIA INSURANCE COMPANY LTD.
IEMs for this tender: Shri Dharam Chand Jain, IPS (Retd.), 4F, Type-VII, Tower-6, East Kidwai Nagar, New Delhi – 110023; and Shri Vijay Sharma, IRSE (Retd.), Flat no.9112, Parx Laureate, Sector 108, Noida, Uttar Pradesh, 201304.
No standing physical bid-submission desk/deadline is prescribed beyond GeM upload; if hard copies are demanded, the RFP address for the Chief Manager, IT Department, HO 7th Floor, 24 Whites Road, Chennai 600014 is the documented authority address.