Bid publication date
GeM Bid Document GEM/2026/B/8012011 is dated 12-09-2026.
- No separate corrigendum revises this date; metadata also lists no corrigenda.
Loading…
Cyber Security Audit - Security Audit of Application and Server
All India Institute Of Medical Sciences (AIIMS) · South Delhi, Delhi9864738
Written by TenderKart AI from the documents published when it was generated. Check the tender for later corrigenda before you bid.
12 Sept 2026
3 Oct 2026
₹70 L
₹2.1 L
All important dates as they stand after corrigenda: publication, pre-bid/clarification deadline, bid submission deadline, bid opening, and bid validity period.
GeM Bid Document GEM/2026/B/8012011 is dated 12-09-2026.
Bid End Date/Time is 03-10-2026 12:00:00.
Bid Opening Date/Time is 04-10-2026 12:00:00.
Bid Offer Validity is 180 days from the bid end date.
Time allowed for Technical Clarifications during technical evaluation is 2 Days.
Contract Period on GeM is 3 Year(s) 1 Day(s); ATC states three (03) years for the VAPT engagement.
Tender value or estimated cost, EMD/bid security (amount, acceptable forms, validity), tender document fees, performance security, and key payment terms.
Estimated Bid Value is INR 70,00,000 (inclusive of all taxes).
EMD Amount is INR 2,10,000; Advisory Bank State Bank of India; beneficiary AIIMS, Main Grant.
ePBG is 5.00% of contract value for 38 months; Advisory Bank SBI; in favour of beneficiary AIIMS, Main Grant.
No tender fee or bid participation fee is charged in this GeM bid.
Quarterly payments against GST invoice after satisfactory completion; no advance; penalties deducted from invoice; GST as per norms.
Every pass/fail eligibility and qualification requirement: experience and past performance, turnover/net worth, registrations and certifications, consortium/JV rules, and debarment or blacklisting conditions.
Bidder must be currently CERT-In empanelled; valid empanelment certificate mandatory at bid submission.
GeM requires 3 years similar service experience plus 40%/50%/80% similar-service value thresholds; ATC separately requires 3 years cybersecurity audit experience and 3 similar VAPT projects for Govt/PSU/Healthcare in last 3 FYs.
Minimum average annual turnover INR 50 Lakh for last 3 years (ending 31 March of previous FY).
Operational office in Delhi/NCR required; vendor must not be blacklisted by any Central/State Govt/PSU/Autonomous Body.
One Junior Auditor onsite for 3 years must meet education, certification, experience and skill thresholds in ATC 7.1.
MSE purchase preference Yes with L1+15% band and 100% quantity to matching MSE service provider; MII Compliance Yes.
Bidders from countries sharing a land border with India are eligible only if registered with the Competent Authority (GeM GTC clause 26); false declaration grounds immediate termination and legal action.
No consortium or JV rules are stated in the bid document or ATC.
What is being procured: the work, supplies or services, deliverables and quantities, locations, phases, completion or delivery timelines, applicable standards, and notable exclusions.
3-year CERT-In empanelled agency engagement for continuous VA/PT of AIIMS applications, physical servers and VMs, with one onsite Junior Auditor at AIIMS New Delhi.
Application, server/VM and database security assessments covering OWASP, external black-box, OS hardening (CIS L1/L2), hypervisor and multi-DB platforms.
Applications: VA monthly, auth/access quarterly, PT half-yearly, re-test as required; Servers/VMs: vuln scan monthly, hardening and privilege review quarterly, PT and compliance yearly, re-test as required.
ATC requires CERT-In directions (incl. 2022), MeitY advisories, ISO/IEC 27001:2022, OWASP Top 10 and Testing Guide v4.2, CVSS v3.1, DPDPA 2023, NABH IT Standards, MoHFW Cybersecurity Guidelines 2023.
L1 VA reports, remediation/re-test till certificate, executive summary, dashboards, annual report, Safe-to-Host certificate; tight SLA timelines and 24-hour critical vulnerability intimation.
The complete checklist of documents to submit — mandatory vs conditional, with any prescribed formats, proformas or annexures — plus how to submit: portal and mode, envelope/cover structure, digital signature requirements, signing and attestation rules, and physical originals with their deadline.
Online two-packet bid on GeM (GEM/2026/B/8012011); Bid to RA enabled with H1-Highest Priced Bid Elimination.
Hard-copy EMD/Bid Security must reach the Buyer within 5 working days of bid opening; other physical pre-qualification document mandates (except EMD and Integrity Pact) are prohibited on GeM.
Security audit reports must be stamped and signed by the authorized signatory (soft + hard copies); NDA to be executed before commencement.
Every corrigendum/addendum in order — what changed (original vs amended value), its impact, and the action for the bidder — ending with the values that finally apply.
No corrigendum or addendum is present in the tender document set; all dates, amounts and conditions stand as in the original GeM bid dated 12-09-2026 and attached ATC/proposal.
Genuine conflicts within and across the documents (original vs corrigenda, clause vs annexure, tender document vs BOQ): both sides with citations, and which value prevails.
Bid page 5 labels four separate files as Scope of Work, NDA format, Network Infrastructure/data-flow diagram, and price-breakup format, but all four PDFs are byte-identical copies of the same TSEC minutes + VAPT proposal.
GeM clause 10 uses value-based similar-service thresholds (3×40% / 2×50% / 1×80% of estimated cost), while ATC section 7 requires three similar VAPT projects for Govt/PSU/Healthcare in last three FYs without stating those value percentages.
GeM technical specifications require compliance against ISO 27001 and ISO 20000; ATC section 5 lists CERT-In, MeitY, ISO/IEC 27001:2022, OWASP, CVSS, DPDPA, NABH and MoHFW guidelines but does not mention ISO 20000.
GeM Bid Details state Contract Period 3 Year(s) 1 Day(s); ATC repeatedly states three (03) years.
ATC scope says all tools/software needed for security audit will be provided by the Junior auditor, while general conditions require all tools/software/licenses used to be genuine/properly licensed (vendor responsibility) and VAPT cost to include all tools.
Only critical, tender-specific pre-bid queries that could materially change bid/no-bid, pricing, eligibility or contractual risk. Skip generic or obvious questions the documents already answer clearly.
Please re-upload the actual NDA proforma, network/data-flow diagram and commercial breakup format; current GeM attachments 1788866392/398/409 are duplicates of the Scope PDF.
If AIIMS increases applications/servers/VMs above the indicative 70/50/200 during the firm 3-year price, will unit rates or change-order pricing apply, or is all variation absorbed in the lump-sum?
Confirm whether bidders must satisfy both GeM 40/50/80% similar-service value criteria and ATC's three VAPT projects for Govt/PSU/Healthcare, and whether MSE/Startup experience relaxation waives any ATC bars (especially CERT-In and VAPT project count).
Is ISO 20000 certification or demonstrated ITSM compliance mandatory for technical acceptance, given it appears only in GeM core specifications and not in ATC section 5?
Clarify expected employment model (vendor payroll only?), PF/payslip verification process, replacement SLA if resource exits before 1-year surety, and who must own commercial VA/PT tool licences used onsite.
Please confirm authorization process, allowed testing windows, production vs staging, and liability allocation for external black-box PT against live healthcare systems.
Commercial, legal and execution risks a bidder should weigh: liquidated damages and penalties, unusual or one-sided clauses, tight timelines, and payment or security risks.
Cash penalties for missed audits, late reports and repeated failures, capped at 10% of quarterly invoice; poor reports trigger re-audit at vendor cost; persistent non-compliance can lead to immediate termination.
Indicative asset counts can be increased/decreased by AIIMS while prices remain firm for 3 years with no additional charges beyond quoted amount.
No advance; quarterly pay only after reports, retests and certified attendance/PF checks; 5% ePBG for 38 months; EMD 2.1 lakh locked through evaluation.
AIIMS may terminate for SLA breach, security incident from vendor negligence, misrepresentation, non-performance or resource failure; may recover losses; arbitration/mediation clauses are No; Delhi jurisdiction only.
NDA and long confidentiality obligations apply, yet GeM setting shows bidder-uploaded documents to all participating bidders—sensitive proposal content may be visible to competitors.
Full-time onsite junior auditor for 3 years with 1-year retention surety; external black-box testing of live clinical/HMIS systems creates high operational and liability exposure.
The inviting authority and relevant contacts: office, person, designation, address, phone and email — and which address receives physical submissions, if any.
Buyer organisation is AIIMS, New Delhi under Department of Health and Family Welfare, Ministry of Health and Family Welfare; Computer Facility issues the VAPT proposal.
HOD Email: [email protected]; Buyer Email: [email protected].
Consignee/Reporting Officer: Sumit; address 1st Floor, New Pvt. Ward, Store Section (CN Centre), AIIMS, Ansari Nagar, New Delhi, PIN 110029.
TSEC chair Dr. Punit Kaur, Prof & HOD Biophysics; other members include Dr. Angel R. Singh, Dr. Vivek Gupta, Mr. Nalin Kaushik (NIC), Dr. Manish Bhardwaj (CSIR); end users Tripta, Sanjeev Kumar, Harish (Computer Facility).