Publication / bid issue
07-07-2026. No corrigendum changing this date is present in the supplied tender documents.
Loading…
Cyber Security Audit - Security and Compliance Audit
National Institute Of Disaster Management · North Delhi, Delhi9531354
Written by TenderKart AI from the documents published when it was generated. Check the tender for later corrigenda before you bid.
7 Jul 2026
8 Aug 2026
All important dates as they stand after corrigenda: publication, pre-bid/clarification deadline, bid submission deadline, bid opening, and bid validity period.
07-07-2026. No corrigendum changing this date is present in the supplied tender documents.
No pre-bid meeting or pre-bid query deadline is specified. During technical evaluation, bidders are allowed 2 days for technical clarifications.
28-07-2026 13:00:00. The portal is configured to auto-extend once by 3 days unless at least 3 bids are received; the stated deadline remains the current date unless that mechanism triggers.
28-07-2026 13:30:00.
180 days from the bid end date.
Tender value or estimated cost, EMD/bid security (amount, acceptable forms, validity), tender document fees, performance security, and key payment terms.
₹36,000 inclusive of all taxes. This figure is stated to guide EMD and eligibility only and is not a pricing benchmark.
No EMD is required and no ePBG/performance security is required. Consequently, the bid specifies no security amount, form, or validity. No tender document fee is stated in the supplied documents.
Quote each of the three websites separately, inclusive of all charges and taxes; NIDM will not pay transportation, accommodation, or other additional fees. Evaluation is total-value-wise and a price breakup is required.
No advance. Payment is released website-by-website only after successful completion and NIC security-audit clearance. The seller must submit the online invoice/GST invoice; the tender-specific milestone overrides the GTC's default monthly billing. NIDM states that 10% TDS will be deducted as per Income Tax rules.
Every pass/fail eligibility and qualification requirement: experience and past performance, turnover/net worth, registrations and certifications, consortium/JV rules, and debarment or blacklisting conditions.
Pass/fail: bidder must be currently enrolled/registered with CERT-In as a third-party empanelled agency for Government/NIC portal audits on NIC Cloud, and must keep that empanelment valid throughout the audit. Expiry during the engagement permits NIDM to reject the work order, subject to competent-authority approval.
Pass/fail: 3 years' experience providing similar services to a Central/State Government organisation or PSU, evidenced for each financial year. In addition, bidder must have completed in the stated look-back period either 3 similar services each at least 40% of estimated cost, 2 each at least 50%, or 1 at least 80%.
Eligible MSEs receive complete relaxation from years-of-experience and turnover criteria, subject to meeting quality/technical specifications and uploading proof. Startup relaxation is not available. MSE purchase preference applies to validated service providers within L1+15%, with 100% quantity available subject to matching L1.
Pass/fail: bidder must be registered with relevant tax authorities such as GST and have a registered office or operational presence in Delhi NCR.
Pass/fail: bidder must be able to deploy a qualified security-audit team for onsite and offsite work and must have a dedicated/toll-free service-support number.
By participating on GeM, bidder undertakes that it is not presently debarred from bidding under Rule 151 of GFR 2017. False local-content declarations can cause debarment for up to two years.
A bidder from a country sharing a land border with India is eligible only if registered with the Competent Authority. Bidder must undertake compliance; a false declaration or non-compliance permits immediate termination and legal action.
What is being procured: the work, supplies or services, deliverables and quantities, locations, phases, completion or delivery timelines, applicable standards, and notable exclusions.
Security and compliance audit of IDRN (https://idrn.nidm.gov.in/), NPDRR (https://npdrr.nidm.gov.in/), and Self Study Portal (https://ssp.nidm.gov.in/), all hosted on NIC Cloud. The GeM quantity is one project/lumpsum-based service at NIDM, Rohini, Delhi.
Assess security posture and controls; identify vulnerabilities/threats/risks; conduct vulnerability assessment and possible penetration testing; review security policies and procedures; test compliance; recommend remediation; and provide technical assistance.
Stage I is vulnerability assessment with a recommendations report. Stage II and subsequent levels validate Stage-I vulnerabilities, rescan until no significant vulnerabilities remain, generate reports, and issue certificates. Submit stage/phase-wise reports plus a final security audit report and certificate for each website; support continues until NIC clears the audit.
IDRN: Windows/IIS 10/ASP.NET MVC 5/MS-SQL Server 2017, 65 pages and 1 login module. NPDRR: Windows/IIS 10/Classic ASP and ASP.NET MVC 5/MS-SQL Server 2017, 40 pages and 1 login module. SSP: Linux/Apache/PHP/MySQL Moodle portal; its page count and login/web-service counts are not provided.
Hybrid deployment. Compliance is required against ISO 27001 ISMS and completion reports/certificates must adhere to CERT-In NIC standards. Overall contract period is 6 months; each website audit has a maximum duration of 3 months from its audit start date.
Auditor may not use, copy, or disclose NIDM databases, source code, workflows, documentation, or related information; after audit it must declare non-copying/non-disclosure. It must also ensure smooth website data synchronisation and provide email/phone support 09:00-18:00 Monday-Friday.
The complete checklist of documents to submit — mandatory vs conditional, with any prescribed formats, proformas or annexures — plus how to submit: portal and mode, envelope/cover structure, digital signature requirements, signing and attestation rules, and physical originals with their deadline.
Submit on GeM as a Two Packet Bid. Put all price elements only in the financial bid; any price in the technical bid makes the offer non-responsive. Evaluation is total-value-wise, no reverse auction is enabled, and a financial price breakup is required.
GeM applies Aadhaar-based e-signing to documents; the GTC states that e-sign is legally at par with digital signatures. The tender does not prescribe a separate DSC class, notarisation, stamping, or attestation rule for bid uploads.
No physical original is required by this bid: EMD is expressly not required, and no other hard-copy submission is specified. All listed bid documents should therefore be uploaded on GeM.
Failure to upload a required certificate/document can cause rejection. Documents submitted later as a clarification or representation will be visible to other participating bidders after login.
Every corrigendum/addendum in order — what changed (original vs amended value), its impact, and the action for the bidder — ending with the values that finally apply.
The AI found nothing to report for this question.
Genuine conflicts within and across the documents (original vs corrigenda, clause vs annexure, tender document vs BOQ): both sides with citations, and which value prevails.
The AI found nothing to report for this question.
Only critical, tender-specific pre-bid queries that could materially change bid/no-bid, pricing, eligibility or contractual risk. Skip generic or obvious questions the documents already answer clearly.
Request the SSP portal's page count, login modules, roles/privileges, web services/APIs and method count, and test-user/access arrangements. Annexure-3 stops at hosting details while the other two annexures quantify pages and logins; this directly affects effort and price.
Clarify the included number of Stage-II/subsequent retests, responsibility and turnaround for remediation, what constitutes a 'significant' vulnerability, and the objective acceptance/SLA for NIC clearance. The current wording makes support and retesting potentially open-ended while payment is entirely conditional on NIC clearance.
Confirm whether the three website audits run in parallel or by NIDM priority, the start date for each site's 3-month clock, and how that fits the 6-month contract. Also identify onsite days, source-code access, credentials, test environment, and NIDM/NIC dependencies.
Commercial, legal and execution risks a bidder should weigh: liquidated damages and penalties, unusual or one-sided clauses, tight timelines, and payment or security risks.
There is no advance; website-wise payment is due only after successful completion and NIC clearance. Rejected services receive no payment. Any delay in NIDM remediation or NIC review could therefore defer cash flow unless responsibilities and acceptance times are clarified.
Stage II expressly includes 'subsequent levels', and technical support continues until NIC clearance. With no stated cap on retests or remediation cycles, bidders carry potentially unpriced effort.
Delay attracts LD at 0.5% of delayed contract value per week or part, normally capped at 5% of total contract value and rising to 10% for inordinate delay (over 25% of the completion period). Non-performance permits cancellation, forfeiture of performance security where applicable, rating downgrade, or GeM debarment.
Buyer may change quantity or contract duration by up to 25% at award and can increase an issued contract by up to 25%; bidders are bound to accept. For lumpsum services, scope and value may increase up to 25% with provider consent.
CERT-In empanelment must remain valid throughout. If it expires during the audit, NIDM reserves the right to reject the work order, creating renewal and continuity risk.
Broad confidentiality prohibits using, copying, or disclosing source code, database, workflows, documentation, and related information, followed by a formal declaration. NIDM retains source-code ownership and all IPR/copyright; bidders should ensure internal handling controls and subcontractor restrictions match these obligations.
The bid has no arbitration or mediation clause; disputes are subject exclusively to competent Delhi courts. Separately, failure to meet declared local content can attract a penalty up to 10% of contract value, and a false declaration can lead to debarment up to two years.
The inviting authority and relevant contacts: office, person, designation, address, phone and email — and which address receives physical submissions, if any.
National Institute of Disaster Management, Ministry of Home Affairs. Reporting officer: Hemant Kumar, NIDM, Plot No. 15, Pocket-3, Block-B, Sector-29, Rohini, Delhi 110042. No physical bid submission is prescribed.
HOD grievance email: [email protected]. Buyer email: [email protected].
Mr. Dharmendra Yadav — mobile 8860697197, telephone 011-20873411; Mr. Amandeep Singh — mobile 9716774666. Both are NIDM technical points of contact for the security audit.