Loading…
Loading…
Tender Value
Refer Docs
Closing Date
9 Oct 2025, 3:00 pmClosed
KANNAUJIA RAJESH
MARKETING CORPORATE, Bharat Petroleum Corporation Limited
ok
22597
1000443433
Single Tender
Buy
MARKETING CORPORATE
14 Jan 2026
1 Oct 2025
9 Oct 2025
1 Oct 2025
9 Oct 2025
1 Oct 2025
DIGITAL BUSINESS
BHARAT PETROLEUM CORPORATION LIMITED
K - Installation, Sewree Fort Road,
Sewree East – Mumbai 400
Single Tender for Procurement and Provisioning of SAP Commerce Cloud for Customer Engagement
Platform (CEP) at Digital Business on nomination basis to OEM M/s SAP India Private Limited.
Tender Number: 22597 CRFQ Number:
Dear Sir/ Madam,
Subject: INVITATION TO BID
1. You are invited to submit your offer as E-bid on C1 India portal, in two-part (techno-commercial
and Price Bid) for the above work on the terms and conditions contained in this tender document.
2. This tender document consists of the following Annexures, which have to be submitted duly signed by
competent authority as per the format in respective Annexures:
I. General conditions of contract Annexure-1
II. Policy and declaration for social media guidelines for businesspartners Annexure-2
III. Non-Disclosure Agreement Annexure-3
IV. Declaration of Holiday Listing/ Liquidation Annexure-4
V. Policy and declaration with respect to restrictions for countries which Annexure-5
share Land border with India
VI PPP-MII Policy and declarations Annexure-6
VII. NEFT Mandate Annexure-7
VIII. Integrity Pact Annexure-8
IX. Performance Security Deposit Annexure-9
X. Earnest Money Deposit Annexure-10
XI Evaluation Methodology Annexure-11
XII Special Conditions of Contract & SLA Annexure-12
XIII. Scope of work and Technical specifications Annexure-13
XIV. Confirmation on Scope understanding & Deviation Statement Annexure-14
XV. Payment Terms Annexure-15
XVI. Billing address Annexure-16
3. Tender details:
SR# Description Applicability
4.1 Type of Job: Goods/ Service/ Works Contract Service Contract
4.2 Divisibility of the tender: Divisible/ Non-divisible Non-divisible
4.3 Purchase Preference (MSE): Applicable/ Not Applicable Not Applicable
4.4 PPP (MII): Applicable/ Not Applicable Not Applicable
4. Your online bid should be submitted on or before the due date of this tender on E-tender system (C1 India
portal - https://bpcltenders.eproc.in ). System will automatically close on the due date and time and bidders
will not be able to submit their bids after the closing time. Bids not in the prescribed format are liable to be
rejected. BPCL does not take any responsibility for any delay in submission of online bids due to connectivity
problem or non-availability of site and/or other documents/instruments to be submitted in physical form due
to postal delay. No claims on this account shall be entertained.
5. The price bid shall be opened only when techno-commercial bid is found to be acceptable. Submission of all
documents, Annexures as listed above, complete as per tender terms is mandatory for acceptance of bid.
6. Bidder shall also have to submit the Undertaking on their Company Letter Head with respect to Compliance
of Restrictions for Countries which share land border with India – as stipulated by Govt. of India, undertaking
for not being on Holiday List & Liquidation and Undertaking with respect to Compliance of Restrictions for
Countries which share land border with India – as stipulated by Govt. of India as per the tender format.
7. Corrigendum/ Addendums if any shall be provided on C1 portal.
8. Your offer is liable to be rejected if there is any deviation from the tender document and its attachment. Kindly
contact us if you need any clarifications before submitting your offer.
9. In case of any clarification pertaining to e-procurement process, the bidder may contact the following
agencies/ personnel:
i. For E-tender related queries please contact:
For E-tender / eProcurement Portal related queries please contact support team ([email protected])
with contact details given as below:.
Name Email ID Number
1 Prathamesh Hadkar [email protected] +91
2 Gourav Panthi +91
3 Saranraj Naicker +91-124-4302000 Ext:
4 Chandan Bera +91
In the event of any query being unresolved, you may escalate to:
SR Name Designation Email ID Number
1 Harshal Sapkale Astt Manager [email protected]
Product Delivery
2 Sachin Toraskar Project Lead – [email protected]
ii. For tender related Technical Queries following can be contacted via e-mail:
Team Member (Digital Business)
Team Lead, LPG (Digital Business) [email protected]
Yours faithfully,
For Bharat Petroleum Corporation
sd/- Amit Kumar
Team Lead, Technical & Contract (Digital Business)
Annexure-1 GENERAL CONDITIONS OF CONTRACT (GCC)
https://ebiz.bpc.co.in/docs/General_Conditions_of_Contract_Updated_080125.pdf
Annexure-2 SOCIAL MEDIA GUIDELINES FOR BUSINESS PARTNERS
Terms & Conditions under Social Media Policy of BPCL for business partners are to provide clear guidance
on acceptable standards of conduct and practices to be followed by the Business Partners of Bharat Petroleum
Corporation Limited, in the usage of social media tools during and post their association with the Corporation.
These terms and conditions are intended to protect and safeguard inter alia the interests and reputation of the
Corporation, in the access, use of or participation on Social Media platforms by such constituents. Successful
bidder/bidders shall have to essentially submit following documents for further evaluation in the tender:
1. “Social Media T&Cs” document along with the bid documents, duly signed & stamped/ digitally signed
by the same signatory who is authorized to sign the bid documents. All the pages of the “Social Media
T&Cs” shall be duly signed. Bidder’s failure to return the “Social Media T&Cs” duly signed along with
the bid documents shall result in the bid not being considered for further evaluation.
• https://ebiz.bpc.co.in/docs/Annexure_Social_Media_Guidelines_for_Business_Partners.pdf
• https://ebiz.bpc.co.in/docs/Declaration_for_Acceptable_Use_of_Social_Media_by_Business_Partn
Annexure-3 NON DISCLOSURE AGREEMENT (To be submitted within 15 days from placement LOI/
https://ebiz.bpc.co.in/docs/NDA_to_be_submitted_by_successful_L1_bidder_before_issuing_PO.pdf
Annexure-4 DECLARATION BY BIDDERS FOR NOT BEING HOLIDAY LISTED & UNDER ANY
https://ebiz.bpc.co.in/docs/UNDERTAKING_OF_NOT_BEING_ON_HOLIDAY_LIST_LIQUIDATION.
Annexure-5 UNDERTAKING WITH RESPECT TO COMPLIANCE OF RESTRICTIONS FOR
COUNTRIES WHICH SHARE LAND BORDER WITH INDIA
Bidders have to submit an undertaking with respect to Compliance of Restrictions for Countries which share
land border with India { Restrictions under Rule 144(xi) of the General Financial Rules, 2017–Reference
OM no. 6/18/2019 – PPD dtd. 23.07.2020 (read along with any subsequent clarifications/amendments
thereof) issued by Ministry of Finance, Public Procurement Division (https://doe.gov.in/procurement-policy-
divisions)}. The declaration to be submitted online on C1 portal.
https://ebiz.bpc.co.in/docs/Format_Restriction_on_Countries_sharing_borders_with_India.pdf
Annexure-6 PPLC: DECLARATIONS FOR PPLC – Not Applicable.
Annexure-7 NEFT MANDATE FORM:
https://ebiz.bpc.co.in/docs/NEFT_MANDATE_FORM_to_be_submitted_by_the_bidder.pdf
Annexure-8 INTEGRITY PACT:
• Pre-signed Integrity Pact shall be uploaded by the Bidder/s along with the technical bid documents, duly
signed and stamped by the authorized signatory.
• All the pages of the Integrity Pact shall be duly signed and witnessed. Bidder's failure to upload the IP
duly signed along with the bid documents shall result in the bid not being considered for further
• If the Bidder has been disqualified from the tender process prior to the award of the contract in
accordance with the provisions of the Integrity Pact, BPCL shall be entitled to demand and recover from
Bidder Liquidated Damages amount by forfeiting the EMD/ Bid Security as per provisions of the
Integrity Pact.
• If the contract has been terminated according to the provisions of the Integrity Pact, or if BPCL is
entitled to terminate the contract according to the provisions of the Integrity Pact, BPCL shall be entitled
to demand and recover from Bidder Liquidated Damages amount by forfeiting the Security Deposit/
Performance Bank Guarantee as per provisions of the Integrity Pact.
• Bidders may raise disputes/complaints if any, with the nominated Independent External Monitor.
• Details of IEM (appointed by CVC) are mentioned below:
Sr. No. Name of IEM E-mail ID
1 Shri Ganesh Vishwakarma [email protected]
2 Shri Atanu Purkayastha [email protected]
3 Shri Pradeep Kumar [email protected]
Annexure-9 PERFORMANCE SECURITY DEPOSIT:
Successful bidder needs to submit the Performance Security Deposit in the form of (Bank Guarantee) of 5%
of basic PO value upfront within 15 days from the receipt of LOA or Contract whichever is earlier. Rest of
the conditions of GCC related to Performance Security Deposit will remain same.
Details for submission of Bank Guarantee (BG) / Performance Bank Guarantee (PBG):
Process for submitting Bank Guarantee / PBG under SFMS (Structured Financial Messaging System) mode
as follows: Bidders / Contractors shall insist their Bank on issuance of SFMS Bank Guarantee for faster
payments. Bidders / Contractors shall provide BPCL's Bank Account No. & IFSC Code (Details given below)
to their Bank as beneficiary at the time of application for Bank Guarantee in favor of BPCL. Issuing Bank
shall issue the Bank Guarantee & send SFMS message to BPCL's Bank confirming the authenticity of Bank
Guarantee who in turn shall send the confirmation to BPCL. Vendor should ensure the following for issue of
E- bank guarantee:
i. The issuing bank is on SFMS platform
ii. SFMS Message type used is 760 COV and SFMS Delivery report/ Message copy is sent along with original
iii. For BG amendment, message type 767COV is to be used.
iv. SFMS contains following details:
a. Beneficiary’s bank name: ICICI Bank
b. IFSC Code: ICIC0000393
c. BPCL'S Customer 1D: 8PCL583493800
v. BG Issuing Bank should send the BG Issuance advice through SFMS to BPCL's designated Banker: ICICI
Bank, Backbay Branch, Mumbai (IFSC: 1CIC0000393).
vi. BG Issuance advice should mention applicable Unique Identifier Code (U1C) in row/ field number
of SFMS Delivery Report.
• BPCL Location : Kharghar , Navi Mumbai
• Head office : Ballard Estate
• UIC : BPCL583493800
vii. The Original BG should be submitted along with print out of SFMS Delivery report from the BG Issuing
viii. SFMS BG will help in faster verification of BGs and prompt release of payments to Vendors.
Annexure-10 EARNEST MONEY DEPOSIT (EMD): Not applicable.
Annexure-11 EVALUATION METHODOLOGY
Part-1 would cover technical and techno-commercial aspects.
Part-2 would be the price bid.
1. Bids will be evaluated firstly as per the Technical & Techno-Commercial requirements of the tender.
2. The price bid will be opened after qualification in technical & techno-commercial evaluations.
3. Being single tender on nomination basis, the work under this tender is non-divisible.
4. Being single tender on a nomination basis, Purchase preference for MSE as per MSME policy of
MoP&NG shall not be applicable.
5. Public Procurement Preference (Make In India) policy shall not be applicable for since the work under
this tender is of proprietary in nature.
6. The bid evaluation and award of the job will be done on an Overall Lowest Landed cost basis.
Annexure-12 SPECIAL CONDITIONS OF CONTRACT
1. Validity of Bid: The validity of bid shall be 120 days from the date of opening of this tender (Technical
Bid). Validity of bid can further be extended on mutual consent between BPCL and Bidders, if required.
2. Currency: Bidders can quote in Indian rupees only.
3. Contract Period : The duration of contract is 3 (Three) years. BPCL and M/s SAP India Private Limited
can mutually extend the contract for another year at the same terms and conditions, with suitable price
adjustment as per the % increase quoted in Price Bid over year 3rd year rates.
4. Performance Security Deposit :
Following 02 options are available with Successful bidder for submitting Performance Security
Successful bidder can submit the Performance Security Deposit of 5 % of contract value upfront
within 15 days from the receipt of LOA. Retention money shall not be deducted from running bills
Successful Bidder opting for deduction of retention money from running bills shall have to submit
the security deposit of Rs. 10 lakhs within 15 days from the receipt of LOA.
Retention money shall be deducted from each running account bill at the rate of 5 % of bill value till
overall amount (security deposit of Rs. 10 lakhs + retention money deducted) of 5 % of contract
value is collected.
In above mentioned both options performance security deposit / security deposit submitted in the
form of Bank guarantee, the Bank Guarantee shall be valid and remain in force till the contractual
completion period, defect liability period and with a claim period of six months thereafter.
5. Additional Terms & Conditions
Terms of delivery
Delivery of SAP Commerce Cloud License along with Cloud Infrastructure as per the TBOM (refer Scope
of Work).Half yearly invoice for the payment against the TBOM shall be raised on delivery of
Software/Infrastructure.
6. Delivery Schedule
a) All Schedules will be calculated from the Zero Date i.e. Date of issuance of Letter of Intent
(LoI)/Purchase Order/Fax of intent/email to this effect, whichever is earlier.
b) Delivery shall be made within 5 days from the zero date for the SAP Commerce Cloud Subscription.
Delivery shall be considered completed only when the SAP Commerce Cloud along with Cloud Infra
as per the tender deliverables are made available and accessible; duly certified by BPCL Officer.
c) Part delivery will not be considered. Even if it is delivered partly, the last shipment as per the
LoI/Purchase Order will be considered as delivered date.
d) Delivery as per the LoI/Purchase Order has to be made before submitting the invoice for payment.
Part payment of the equipment will not be made other than payment terms.
e) Vendor to provide complete bill of materials with part numbers which will be required to identify
proper delivery.
f) Vendor shall submit the details of the deployment of SAP Commerce Cloud Infrastructure and
Services as per the tender terms & condition and provide access for validation of deliverables.
Anenxure-12A Service level Agreement (SLA) & Penalty
The SLA will define the level of service which shall be provided by the selected bidder to BPCL for duration
of the contract which shall be awarded and executed with the selected bidder post this RFP.
If the Monthly Uptime Percentage for The System Availability Service Level for the Cloud Services(“SA
SLA”) not met as mentioned in the below table for any given month, BPCL will impart penalty as follows:
Service level Service Penalty
PRD: 99.99% System Availability 2% of the Monthly Subscription Fees for the affected
percentage excluding scheduled downtime subscription-based Cloud Service or the monthly Cloud
(Maintenance Window) during each Month Credits consumed for the affected consumption-based
for the production version of the Cloud Cloud Service, for each 1% below the System
Service. Availability SLA, not to exceed 100% of the fees for
the relevant Month for the affected Cloud Service.
“System Availability Percentage” is calculated and defined as follows:
(Total Minutes in the Month−Excluded Downtime – Downtime)/ (Total Minutes in the Month−Excluded
Following clause is applicable for the entire contract :
Financial Losses
Bidder shall be completely liable for financial losses to BPCL on
account of incidents like security breach, data breach,
malfunction of application software, erroneous code logic,
process, system failure for which bidder is responsible. Liability
will be in accordance to the “ General Conditions of Contract -
Limitation of Liability " Clause.
Annexure-13 Scope of work and Technical specifications
The scope of this proposal is to :
“Supply and provision of SAP Commerce Cloud as a subscription (including cloud infrastructure, support, and
enhanced operations services) for a period of 3 years.”
Important Notes to Bidder
1. While preparing this document, BPCL has included all the requirements in the bid. However,
bidder must examine this document for delivering the project as per the Scope of work and consider
additional required components, if any, in the submitted commercial bids. Once the bid is
technically accepted & commercially evaluated, it is the responsibility of the bidder to complete
the Project, as per the Scope, without any commercial impact to BPCL.
2. Jobs awarded under this contract cannot be sub-contracted.
2.0 Scope for SAP Commerce Cloud
2.1 General Scope
1. Providing SAP Commerce Cloud solution for BPCL.
2. To provide all the necessary software including SAP Commerce Software on subscription basis
(comprising of software, software support, cloud Infrastructure) and enhanced operations
services as specified in Annexure- I.
3. Providing 24x7 technical monitoring and operations support for Production system including
4. M/s. SAP must fulfill technical delivery. M/s. SAP shall be responsible for system monitoring
and maintenance (alerts, technical upgrades, installations, etc.).
5. M/s. SAP must provide network security to the proposed environment.
6. SAP Commerce data must be secured by proper encryption and decryption mechanism.
7. SOC report to be provided to BPCL on annual basis or whenever the latest report is
8. Provisioning of Data center on cloud environment with DR (Disaster Recovery) site at
different geographic location within India and maintaining the same.
9. M/s. SAP to establish DR set up from Go-Live date with RTO of 24 Hours and RPO of
10. To maintain adequate data security measures as per guidelines of SAP prescribed security,
consistent with industry standards and technology best practices, to protect BPCL business
data from unauthorized disclosure or acquisition by an unauthorized person.
11. To maintain data confidentiality and not to share/disclose any of the information stored on the
cloud with any person, firm, or organization.
12. BPCL’s data should not be used for personal or commercial use by any means.
13. Cloud infrastructure should be hosted in India-based Data Centre. No BPCL’s data should be
stored in any Data Centre outside the boundaries of India.
14. The hyperscaler should be MEITY empaneled cloud service provider (CSP).
15. Backup of the data for safe keeping. M/s. SAP shall provide full backup of BPCL data to BPCL
and validate the same for future use after completion of Tenure of this contract.
16. On completion of tenure of contract, once the data is backed up and provided to BPCL, given
confirmation of the same by BPCL, related data on cloud must be removed/deleted from all the
17. The SAP Commerce Cloud provided should be accessible to BPCL from the cloud data centre
using VPN/MPLS/Lease Line/Internet.
18. M/s. SAP must examine the TBoM mentioned in Annexure-I and supply the appropriate
licenses and managed services for running the SAP Commerce Cloud for the next 3 years.
19. Bidder to provide non Production system(s) (Development & Quality) for SAP Commerce
Cloud as detailed in Annexure-I
20. The solutions for statutory changes to be provided free of cost to adhere to timelines set by
statutory authorities.
2.2 Solution capabilities and features:
a. Requirements for Audit Trail Functionality / Edit Log Feature requirement as per
Companies (Accounts) Rules,
Beginning April 1st, 2023, Companies which use accounting software for maintaining their
books of account, are required to use only such accounting software which has audit trail
feature. The New Proviso to Rule 3(1) of Companies (Accounts) Rules,2014 states that -
every company that uses accounting software to maintain its books of account shall use only
Accounting Software that has a feature of recording an:
• Audit Trail of each and every transaction,
• Creating an edit log of each change made in books of account along with the date
when such changes were made.
• Ensuring that the audit trail cannot be disabled.
The BIDDER needs to ensure that the applications being developed/developed in the scope
of this RFP abide to the provisions of the above act (where applicable, necessarily for
Applications integrated with BPCL’s SAP ERP System).
Information that needs to be captured shall include when changes were made, who made
those changes, and what data was changed. The audit trail feature shall be available at the
database level also for logging any direct data changes. It is to be ensured that Audit trail
feature is always enabled and effective throughout the period and that the feature is
appropriately protected from any modification. Further, the audit trail log shall be retained
as per statutory requirements i.e. for a minimum of 8 years and that same can be retrieved
and presented to stakeholders whenever required even in case of future changes/upgradation
in application or change in BIDDER.
BIDDER to provide the Independent Auditor’s report issued in terms of Audit Standards
such as SOC 2/SAE 3402. The report shall specifically cover that audit trail for the
application is maintained in line with the requirements of the Companies Act, 2013 and that
the report shall cover the period of the company’s financial reporting period.”
▪ Data Encryption /Security of information
1. All data flows from other systems into SAP Commerce Cloud system will be encrypted
as per the standards/ methodology. Bidder should specify the supported standards/
2. All data residing in SAP Commerce Cloud system shall be stored in encrypted format.
3. It shall be responsibility of bidder to issue technical solutions & operational
instructions for data security and BPCL would endeavor to adopt the same.
4. Bidder undertakes to treat information passed on to them under this tender as
Confidential. Such information will not be communicated/published/advertised by
them to media / organization / any person other than its representatives whose access
is necessary to enable it to exercise its rights or perform its rights or perform its
obligations under the Agreement, without expressive permission of BPCL in writing.
5. BPCL Team shall be permitted to perform application penetration test of SAP Cloud
Services upon mutual agreement after subscription to the Cloud Service. All the
discovered vulnerabilities shall be addressed by the bidder appropriately to mitigate
the identified risks.
6. Bidder need to comply with following
• BPCL Security Checklist for Cloud/ Third-party solutions (Annexure – III)
▪ Disaster Recovery
Bidder shall provide standard disaster recovery (DR) setup. DR setup should reside in India.
RTO of 24 Hours and RPO of 60 Mins. For moving from Standard to Premium DR, there
should be no technical constraint from product end.
▪ Cyber Incident
1. Bidder shall immediately report out instances of cyber-attack / access of BPCL systems by
un-authorized users at any stage of data flow between systems along with all the relevant
details in writing as mandated by cyber security law of India. Additionally, bidder shall
bring to notice of BPCL any instances of security breach immediately. .
2. In case of any InfoSec breach bidder shall ensure that application is restored to last healthy
configuration. Further, bidder may submit to BPCL management a Root Cause Analysis
(RCA) describing the details of the breach and measures taken. Further, bidder shall submit
to BPCL management a Root Cause Analysis (RCA) covering attack description and
methodology, extent of compromise, loss of data, if any, mitigation and countermeasures
to prevent future attacks
3. BPCL, in the event of a cyber-attack on the application, may appoint one or more of its
officers or engage external party for incident investigation in which case bidder shall
extend full cooperation and support and shall work under the direction of appointed team.
4. Bidder shall make available the security certification and attestations for the subscribed
Cloud Service (e.g., ISO 27001, SOC 2, or other comparable reports) to BPCL. BPCL shall
have right to perform an annual application penetration test of SAP Cloud Services and
shall be permitted upon mutual agreement after subscription to the Cloud Service.
Vulnerability, if any, found any needs to be fixed immediately.
5. System Security shall be as per ISO
6. Network Security: At Network level, firewalls are deployed with multi-layer defence
control. Secured Socket Layer certificates are used for end-to-end encryption that supports
data confidentiality.
7. Server firmware and Operating System: Bidder shall ensure patching and hardening of
server firmware and operating system are done as per industry standards.
8. Security Patching: Bidder shall perform security patching of application and underline
infrastructure on monthly basis or as it is released in case of zero-day vulnerability.
e. Confidentiality/Privacy
1. Bidder shall ensure that any data made available offline for purpose of development and
testing during contract period shall be irreversibly destroyed after the expiry of contract
2. Bidder shall ensure that application data is not archived or stored, partly or fully, except in
a restorable ‘backup’ form.
f. Other services to be provided by Bidder
At the end of the contract, bidder shall
a) Hand over data in their custody in whatever form they are holding to BPCL and/or to
BPCL identified 3rd party at no-extra cost.
2.3 Delivery Timelines:
The infra detailed in Annexure I to be provisioned within 5 days of Purchase Order or Signing of SAP Order
ANNEXURE - I: Technical Bill of Material- TBoM
Item Description Unit Year 1 Year 2 Year
32 vCore / 8 32 vCore / 8 32 vCore /
SAP Commerce Cloud, vCore / TB TB TB
Pro Ed DataBase Georeplication Georeplication Georeplication
- "Yes" - "Yes" - "Yes"
40 vCore / 10 80 vCore / 10 80 vCore /
SAP Commerce Cloud, vCore / TB TB TB
Code Replication DataBase Georeplication Georeplication Georeplication
- "Yes" - "Yes" - "Yes"
SAP Commerce Cloud,
Consumption Credits
8 Env (2 8 Env (2
SAP Commerce Cloud vCore / 8 Env (2 vCore
4 vCore / 500 vCore /
Non Prod Environment DataBase / 500 GB)
SAP Commerce Cloud,
SAP Commerce Cloud,
Enhance Ops, Access
7 VPN Tunnel Count Min 20 Min 20 Min
(Subscription Level)
Cloud Media Storage
(Subscription Level)
Sr.No Metric Measure
1 Number of Orders (Subscription Level for 3 Years) 200 Cr
2 P1 - Peak Orders Per/Minute 317 K
3 P2 - Peak Orders Per/Minute 36.5 K
1. Using Consumption Credits, BPCL will be able to scale-up non-production tenants as per business and
technical requirements.
2. Using Scalability Add-ons BPCL will be able to scale-up both production as well as non-production
tenants as per business and technical requirements
Annexure II - System Availability Service Level for SAP Commerce Cloud and support SLA
If the Monthly Uptime Percentage for The System Availability Service Level for the Cloud Services(“SA SLA”)
not met as mentioned in the below table for any given month, BPCL will impart penalty as follows:
Service level Service Penalty
PRD: 99.99% System Availability 2% of the Monthly Subscription Fees for the affected
percentage excluding scheduled downtime subscription-based Cloud Service or the monthly Cloud
(Maintenance Window) during each Month Credits consumed for the affected consumption-based
for the production version of the Cloud Cloud Service, for each 1% below the System
Service. Availability SLA, not to exceed 100% of the fees for
the relevant Month for the affected Cloud Service.
“System Availability Percentage” is calculated and defined as follows:
(Total Minutes in the Month−Excluded Downtime – Downtime)/ (Total Minutes in the Month−Excluded
Following clause is applicable for the entire contract :
Bidder shall be completely liable for financial losses to BPCL on
account of incidents like security breach, data breach,
malfunction of application software, erroneous code logic,
Financial Losses
process, system failure for which bidder is responsible. Liability
will be in accordance to the “ General Conditions of Contract -
Limitation of Liability " Clause.
Annexure-III Security Checklist for Cloud/ Third-party solutions
1. Non-Disclosure Agreement (NDA) should be signed between BPCL and the Contracting Agency (on
Rs.500/- non-judicial stamp paper) as well as between contracting agency and their service providers
before the start of contract. NDA should be signed by the contracting agency as well as BPCL signatory.
No data should be shared before signing of the NDA.
2. Data centre on which the application to be hosted should preferably be within India, unless there is a
strong justification for hosting it outside and acceptable to BPCL.
3. Access to the applications should be preferably restricted to India Region; subject to business and
technical requirements.
4. Cloud Service Provider or the Data Centre Provider should maintain accreditation by MeitY or Local
accreditation agency (for data hosted outside India).
5. Cloud Service Provider or the Data Centre Provider should maintain relevant security standards. e.g.
a. ISO/IEC 27001 (Information Security Management)
b. ISO/ IEC 27017 (Code of practice for securing cloud services)
c. ISO/IEC 27018 (Code of Practice for Protecting Personal Data)
6. Solution provider should submit the detailed asset inventory, application & database platform and
network architecture details as per template shared by BPCL.
7. Backups of all components are taken periodically (periodicity to be decided by the business) to ensure
the availability of data & the relevant applications in case of a major failure or a security incident.
8. Network/ perimeter should be protected through a Firewall and intrusion protection system (IPS / IDS).
9. All components including Operating System, DB, Web server, application server, Network & Security
systems etc. should be hardened before deployment of any new solution with minimum of following
(but not limited to) controls: -
a. Local Administrator accounts should be renamed.
b. Unused accounts should be disabled or deleted.
c. Guest accounts should be disabled.
d. Default passwords should be changed.
e. All unused ports and services should be disabled or removed.
f. Account lock-out policy should be configured.
g. All applicable security updates/patches should be installed.
10. Timestamp of all system components should be in sync with the Network Time Protocol (NTP) servers
of National Informatics Centre (NIC) or National Physical Laboratory (NPL).
11. Patching and reboot of systems (if applicable) should be done on periodic basis.
12. The servers should be protected through a leading Anti-malware/ EDR / XDR solution.
13. Data in transit should be encrypted using TLS1.2 or above.
14. The data at rest should be encrypted with AES-256 encryption algorithm or above.
15. Validity of all TLS certificates shall be monitored and replaced/ renewed before their expiry. Certificate
files and their private keys shall be kept under strict access control.
16. Passwords should be complex and not easily guessable or common phrases. Passwords should not be
hardcoded in any program/ script. Passwords should be changed periodically (between 42 to 90 days).
17. Access to the solution should be configured with multi-factor authentication and Role-based Access
18. Administrator/ Privilege access extended to the personnel of solution provider should be logged and
reviewed periodically.
19. All whitelisted IP addresses should have access only to a specific service/ ports.
20. All outgoing access from servers to Internet must be restricted through limited IP addresses or URLs as
per the business requirement.
21. Except production applications, all other application and systems (including development, UAT, DB and
other infrastructure components) should not have direct access to production or live BPCL data. The same
should be reviewed from time to time.
22. The platform provider should ensure regular Vulnerability Assessment Penetration Testing (Level1 and
Level2) for the platform provided to BPCL should be done through CERT-In empaneled auditor:
i. before initial roll-out,
ii. subsequently once in a year.
and submit Level2 report to BPCL.
23. Further the chatbot solution built for BPCL on the platform must undergo the WAPT audit conducted by
BPCL’s internal/external auditor before any go-live of the application, use cases, workflows. The solution
provider should provide the parameters to audit the solution by 3rd party auditors (for security) and any
vulnerability observed shall be rectified by the bidder without any additional cost to BPCL.
24. All identified vulnerabilities need to be closed before deploying the solution into production.
25. Vulnerabilities identified either through VAPT/ WAPT or through other mediums (disclosure by OEM,
advisories by statutory agencies, tool-based scanning etc.) should be patched as per below timelines:
i. Critical – 3 days
ii. High – 5 days
iii. Medium – 15 days
iv. Low – 21 days
26. Any unused published web services/ APIs should be taken down.
27. All types of clear-text protocols such as TELNET, FTP etc. must be disabled.
28. Software with valid licenses & support should only be deployed.
29. In case the solution provider has used an open-source or third-party software codes/ libraries in building
the offered software, then they should ensure such components are secured by design. In addition, solution
provider should share the Software Bill of Materials (SBOM) for all open-source components with
30. The solution provider must conduct all necessary checks to ensure that any open-source or third-party
software codes/ libraries used in building the offered software does not have any embedded security threat
such as malware, rootkit, remote access trojans or backdoor etc.
31. All Internet-facing web applications should have Web Application Firewall (WAF), Anti-DDoS, Anti-
BOT, API security protection enabled.
32. Logging should be enabled at all layers of the infrastructure and logs to be provided for auditing/ forensic
investigations as and when requested by BPCL. All security, access & transaction logs should be retained
for minimum 180 days.
33. Change Management process should be followed for making changes in the solution as well as in the
infrastructure.
34. The solution should be governed through continuous monitoring & response (identify-protect-detect-
respond-recover) from any security incident/ data breach.
35. The solution provider should follow secure software development lifecycle practices (including Static
Application Security Testing, source code review, etc.) to develop & maintain the software being offered.
36. Solution shall validate all user inputs appropriately to ensure the input is consistent with the requirement
and follows permitted lengths and formats.
37. Adequate measures shall be taken by the solution provider to ensure that the solution or any of its
components does not have any malware (such as trojan, backdoor, spyware, miner etc.) installed in it.
Solution provider shall provide an assurance letter/undertaking on their letter head to BPCL in this regard. Commented [jh1]: Is there any format?
38. The solution must implement robust security measures to protect AI models, data and infra from cyber
threats and unauthorized access
39. AI models used in the solution should be protected against various AI-specific attacks such as prompt
injection and adversarial inputs.
40. All communication to the solution and associated APIs should be protected using rate-limiting,
authentication and authorization controls.
41. The Solution should have compartmentalization techniques that have been employed to isolate BPCL
data from other customers’ data. Also, the platform should perform regular backup and recovery tests to
assure that logical segregation and controls are effective.
42. The provider should ensure that no removable media policy or program (CDs, DVDs, tapes, disk drives)
are permissible on their employees’ desktop/laptop/devices. All devices used by the vendor’s employees
to access the platform should have adequate security controls in place and should be approved by vendor’s
43. The solution should have safeguards to protect itself from various attacks including OWASP Top10,
different types of Injection attacks, Cross Site scripting etc.
44. The solution should restrict upload of specific types of files extensions, file size and content type. Eg:
45. The solution should demonstrate sufficient protection against redirection flaws and click-jacking attacks.
46. The solution provider must notify BPCL immediately as soon as they know or believe that a Cyber
Security Incident/ Breach of Data/ Loss of Information has or may have taken place and must provide
full details of the incident and any mitigation measures already taken and intended to be taken by them
and (where applicable) any mitigation measures recommended by them to be taken by BPCL.
47. Following a Cyber Security Incident involving BPCL’s services/ data, the solution provider should:
a. use their best endeavours to mitigate the impact of the Cyber Security Incident, e.g. if any system
is reported under breach/ incident, the solution provider should disconnect it from the network
immediately to contain its lateral movement.
b. extend all necessary support and assistance to BPCL for carrying out incident analysis/ forensic
investigation till its conclusion.
c. ensure to preserve the digital evidence and logs till the conclusion of the investigation and
confirmation from BPCL about the deletion of the evidence.
d. take any action deemed necessary by BPCL in the circumstances, including complying with any
additional security measures deemed appropriate by BPCL.
The solution provider shall ensure to comply with the Digital Personal Data Protection Act 2023 and
Aadhaar Act 2016 (if applicable) for storing and processing of all kinds of Digital Personal Data (DPD) and
Sensitive Personal Data or Information (SPDI)
Important Notes to Bidder
3. While preparing this document, BPCL has included all the requirements in the bid. However, bidder must
examine this document for delivering the project as per the Scope of work and consider additional required
components, if any, in the submitted commercial bids. Once the bid is technically accepted & commercially
evaluated, it is the responsibility of the bidder to complete the Project, as per the Scope, without any
commercial impact to BPCL.
4. Jobs awarded under this contract cannot be sub-contracted.
2.0 Scope for SAP Commerce Cloud
2.1 General Scope
21. Providing SAP Commerce Cloud solution for BPCL.
22. To provide all the necessary software including SAP Commerce Software on subscription basis
(comprising of software, software support, cloud Infrastructure) and enhanced operations services as
specified in Annexure- I.
23. Providing 24x7 technical monitoring and operations support for Production system including
24. M/s. SAP must fulfill technical delivery. M/s. SAP shall be responsible for system monitoring and
maintenance (alerts, technical upgrades, installations, etc.).
25. M/s. SAP must provide network security to the proposed environment.
26. SAP Commerce data must be secured by proper encryption and decryption mechanism.
27. SOC report to be provided to BPCL on annual basis or whenever the latest report is published.
28. Provisioning of Data center on cloud environment with DR (Disaster Recovery) site at different
geographic location within India and maintaining the same.
29. M/s. SAP to establish DR set up from Go-Live date with RTO of 24 Hours and RPO of 60 Mins
30. To maintain adequate data security measures as per guidelines of SAP prescribed security, consistent
with industry standards and technology best practices, to protect BPCL business data from
unauthorized disclosure or acquisition by an unauthorized person.
31. To maintain data confidentiality and not to share/disclose any of the information stored on the cloud
with any person, firm, or organization.
32. BPCL’s data should not be used for personal or commercial use by any means.
33. Cloud infrastructure should be hosted in India-based Data Centre. No BPCL’s data should be stored
in any Data Centre outside the boundaries of India.
34. The hyperscaler should be MEITY empaneled cloud service provider (CSP).
35. Backup of the data for safe keeping. M/s. SAP shall provide full backup of BPCL data to BPCL and
validate the same for future use after completion of Tenure of this contract.
36. On completion of tenure of contract, once the data is backed up and provided to BPCL, given
confirmation of the same by BPCL, related data on cloud must be removed/deleted from all the sources.
37. The SAP Commerce Cloud provided should be accessible to BPCL from the cloud data centre using
VPN/MPLS/Lease Line/Internet.
38. M/s. SAP must examine the TBoM mentioned in Annexure-I and supply the appropriate licenses and
managed services for running the SAP Commerce Cloud for the next 3 years.
39. Bidder to provide non Production system(s) (Development & Quality) for SAP Commerce Cloud as
detailed in Annexure-I
40. The solutions for statutory changes to be provided free of cost to adhere to timelines set by statutory
2.2 Solution capabilities and features:
b. Requirements for Audit Trail Functionality / Edit Log Feature requirement as per Companies
(Accounts) Rules,
Beginning April 1st, 2023, Companies which use accounting software for maintaining their books of
account, are required to use only such accounting software which has audit trail feature. The New Proviso
to Rule 3(1) of Companies (Accounts) Rules,2014 states that - every company that uses accounting
software to maintain its books of account shall use only Accounting Software that has a feature of recording
• Audit Trail of each and every transaction,
• Creating an edit log of each change made in books of account along with the date when such changes
• Ensuring that the audit trail cannot be disabled.
The BIDDER needs to ensure that the applications being developed/developed in the scope of this RFP
abide to the provisions of the above act (where applicable, necessarily for Applications integrated with
BPCL’s SAP ERP System).
Information that needs to be captured shall include when changes were made, who made those changes,
and what data was changed. The audit trail feature shall be available at the database level also for logging
any direct data changes. It is to be ensured that Audit trail feature is always enabled and effective
throughout the period and that the feature is appropriately protected from any modification. Further, the
audit trail log shall be retained as per statutory requirements i.e. for a minimum of 8 years and that same
can be retrieved and presented to stakeholders whenever required even in case of future
changes/upgradation in application or change in BIDDER.
BIDDER to provide the Independent Auditor’s report issued in terms of Audit Standards such as SOC
2/SAE 3402. The report shall specifically cover that audit trail for the application is maintained in line with
the requirements of the Companies Act, 2013 and that the report shall cover the period of the company’s
financial reporting period.”
▪ Data Encryption /Security of information
7. All data flows from other systems into SAP Commerce Cloud system will be encrypted as per
the standards/ methodology. Bidder should specify the supported standards/ methodology.
8. All data residing in SAP Commerce Cloud system shall be stored in encrypted format.
9. It shall be responsibility of bidder to issue technical solutions & operational instructions for data
security and BPCL would endeavor to adopt the same.
10. Bidder undertakes to treat information passed on to them under this tender as Confidential.
Such information will not be communicated/published/advertised by them to media /
organization / any person other than its representatives whose access is necessary to enable it to
exercise its rights or perform its rights or perform its obligations under the Agreement, without
expressive permission of BPCL in writing.
11. BPCL Team shall be permitted to perform application penetration test of SAP Cloud Services
upon mutual agreement after subscription to the Cloud Service. All the discovered
vulnerabilities shall be addressed by the bidder appropriately to mitigate the identified risks.
12. Bidder need to comply with following
• BPCL Security Checklist for Cloud/ Third-party solutions (Annexure – III)
▪ Disaster Recovery
Bidder shall provide standard disaster recovery (DR) setup. DR setup should reside in India. RTO of
Hours and RPO of 60 Mins. For moving from Standard to Premium DR, there should be no technical
constraint from product end.
▪ Cyber Incident
9. Bidder shall immediately report out instances of cyber-attack / access of BPCL systems by un-
authorized users at any stage of data flow between systems along with all the relevant details in writing
as mandated by cyber security law of India. Additionally, bidder shall bring to notice of BPCL any
instances of security breach immediately. .
10. In case of any InfoSec breach bidder shall ensure that application is restored to last healthy
configuration. Further, bidder may submit to BPCL management a Root Cause Analysis (RCA)
describing the details of the breach and measures taken. Further, bidder shall submit to BPCL
management a Root Cause Analysis (RCA) covering attack description and methodology, extent of
compromise, loss of data, if any, mitigation and countermeasures to prevent future attacks
11. BPCL, in the event of a cyber-attack on the application, may appoint one or more of its officers or
engage external party for incident investigation in which case bidder shall extend full cooperation and
support and shall work under the direction of appointed team.
12. Bidder shall make available the security certification and attestations for the subscribed Cloud Service
(e.g., ISO 27001, SOC 2, or other comparable reports) to BPCL. BPCL shall have right to perform an
annual application penetration test of SAP Cloud Services and shall be permitted upon mutual
agreement after subscription to the Cloud Service. Vulnerability, if any, found any needs to be fixed
13. System Security shall be as per ISO
14. Network Security: At Network level, firewalls are deployed with multi-layer defence control.
Secured Socket Layer certificates are used for end-to-end encryption that supports data
confidentiality.
15. Server firmware and Operating System: Bidder shall ensure patching and hardening of server
firmware and operating system are done as per industry standards.
16. Security Patching: Bidder shall perform security patching of application and underline infrastructure
on monthly basis or as it is released in case of zero-day vulnerability.
e. Confidentiality/Privacy
3. Bidder shall ensure that any data made available offline for purpose of development and testing during
contract period shall be irreversibly destroyed after the expiry of contract period.
4. Bidder shall ensure that application data is not archived or stored, partly or fully, except in a restorable
f. Other services to be provided by Bidder
At the end of the contract, bidder shall
b) Hand over data in their custody in whatever form they are holding to BPCL and/or to BPCL
identified 3rd party at no-extra cost.
2.3 Delivery Timelines:
The infra detailed in Annexure I to be provisioned within 5 days of Purchase Order or Signing of SAP
ANNEXURE - I: Technical Bill of Material- TBoM
Item Description Unit Year 1 Year 2 Year
32 vCore / 8 TB 32 vCore / 8 TB 32 vCore / 8 TB
SAP Commerce vCore /
1 Georeplication - Georeplication - Georeplication -
Cloud, Pro Ed DataBase
"Yes" "Yes" "Yes"
40 vCore / 10 80 vCore / 10 80 vCore /
vCore / TB TB TB
DataBase Georeplication - Georeplication - Georeplication -
"Yes" "Yes" "Yes"
3 Cloud, Consumption CU 6,10,832 6,10,832
vCore / 8 Env (2 vCore 8 Env (2 vCore 8 Env (2 vCore
4 Cloud Non Prod
DataBase / 500 GB) / 500 GB) / 500 GB)
Cloud, Enhanced Ops
6 Cloud, Enhance Ops, Ls 1 1
7 VPN Tunnel Count Min 20 Min 20 Min
(Subscription Level)
Cloud Media Storage
(Subscription Level)
Sr.No Metric Measure
1 Number of Orders (Subscription Level for 3 Years) 200 Cr
2 P1 - Peak Orders Per/Minute 317 K
3 P2 - Peak Orders Per/Minute 36.5 K
3. Using Consumption Credits, BPCL will be able to scale-up non-production tenants as per business
and technical requirements.
4. Using Scalability Add-ons BPCL will be able to scale-up both production as well as non-production
tenants as per business and technical requirements
Annexure II - System Availability Service Level for SAP Commerce Cloud and support SLA
If the Monthly Uptime Percentage for The System Availability Service Level for the Cloud Services(“SA
SLA”) not met as mentioned in the below table for any given month, BPCL will impart penalty as follows:
Service level Service Penalty
PRD: 99.99% System Availability 2% of the Monthly Subscription Fees for the affected
percentage excluding scheduled downtime subscription-based Cloud Service or the monthly Cloud
(Maintenance Window) during each Month Credits consumed for the affected consumption-based
for the production version of the Cloud Cloud Service, for each 1% below the System
Service. Availability SLA, not to exceed 100% of the fees for
the relevant Month for the affected Cloud Service.
“System Availability Percentage” is calculated and defined as follows:
(Total Minutes in the Month−Excluded Downtime – Downtime)/ (Total Minutes in the Month−Excluded
Following clause is applicable for the entire contract :
Bidder shall be completely liable for financial losses to BPCL on
account of incidents like security breach, data breach,
malfunction of application software, erroneous code logic,
Financial Losses
process, system failure for which bidder is responsible. Liability
will be in accordance to the “ General Conditions of Contract -
Limitation of Liability " Clause.
Annexure-III Security Checklist for Cloud/ Third-party solutions
48. Non-Disclosure Agreement (NDA) should be signed between BPCL and the Contracting Agency
(on Rs.500/- non-judicial stamp paper) as well as between contracting agency and their service
providers before the start of contract. NDA should be signed by the contracting agency as well as
BPCL signatory. No data should be shared before signing of the NDA.
49. Data centre on which the application to be hosted should preferably be within India, unless there is a
strong justification for hosting it outside and acceptable to BPCL.
50. Access to the applications should be preferably restricted to India Region; subject to business and
technical requirements.
51. Cloud Service Provider or the Data Centre Provider should maintain accreditation by MeitY or Local
accreditation agency (for data hosted outside India).
52. Cloud Service Provider or the Data Centre Provider should maintain relevant security standards.
e. ISO/IEC 27001 (Information Security Management)
f. ISO/ IEC 27017 (Code of practice for securing cloud services)
g. ISO/IEC 27018 (Code of Practice for Protecting Personal Data)
53. Solution provider should submit the detailed asset inventory, application & database platform and
network architecture details as per template shared by BPCL.
54. Backups of all components are taken periodically (periodicity to be decided by the business) to ensure
the availability of data & the relevant applications in case of a major failure or a security incident.
55. Network/ perimeter should be protected through a Firewall and intrusion protection system (IPS /
56. All components including Operating System, DB, Web server, application server, Network &
Security systems etc. should be hardened before deployment of any new solution with minimum of
following (but not limited to) controls: -
h. Local Administrator accounts should be renamed.
i. Unused accounts should be disabled or deleted.
j. Guest accounts should be disabled.
k. Default passwords should be changed.
l. All unused ports and services should be disabled or removed.
m. Account lock-out policy should be configured.
n. All applicable security updates/patches should be installed.
57. Timestamp of all system components should be in sync with the Network Time Protocol (NTP)
servers of National Informatics Centre (NIC) or National Physical Laboratory (NPL).
58. Patching and reboot of systems (if applicable) should be done on periodic basis.
59. The servers should be protected through a leading Anti-malware/ EDR / XDR solution.
60. Data in transit should be encrypted using TLS1.2 or above.
61. The data at rest should be encrypted with AES-256 encryption algorithm or above.
62. Validity of all TLS certificates shall be monitored and replaced/ renewed before their expiry.
Certificate files and their private keys shall be kept under strict access control.
63. Passwords should be complex and not easily guessable or common phrases. Passwords should not
be hardcoded in any program/ script. Passwords should be changed periodically (between 42 to
64. Access to the solution should be configured with multi-factor authentication and Role-based
Access Control.
65. Administrator/ Privilege access extended to the personnel of solution provider should be logged and
reviewed periodically.
66. All whitelisted IP addresses should have access only to a specific service/ ports.
67. All outgoing access from servers to Internet must be restricted through limited IP addresses or URLs
as per the business requirement.
68. Except production applications, all other application and systems (including development, UAT, DB
and other infrastructure components) should not have direct access to production or live BPCL data.
The same should be reviewed from time to time.
69. The platform provider should ensure regular Vulnerability Assessment Penetration Testing (Level1
and Level2) for the platform provided to BPCL should be done through CERT-In empaneled auditor:
iii. before initial roll-out,
iv. subsequently once in a year.
and submit Level2 report to BPCL.
70. Further the chatbot solution built for BPCL on the platform must undergo the WAPT audit conducted
by BPCL’s internal/external auditor before any go-live of the application, use cases, workflows. The
solution provider should provide the parameters to audit the solution by 3rd party auditors (for
security) and any vulnerability observed shall be rectified by the bidder without any additional cost
71. All identified vulnerabilities need to be closed before deploying the solution into production.
72. Vulnerabilities identified either through VAPT/ WAPT or through other mediums (disclosure by
OEM, advisories by statutory agencies, tool-based scanning etc.) should be patched as per below
v. Critical – 3 days
vi. High – 5 days
vii. Medium – 15 days
viii. Low – 21 days
73. Any unused published web services/ APIs should be taken down.
74. All types of clear-text protocols such as TELNET, FTP etc. must be disabled.
75. Software with valid licenses & support should only be deployed.
76. In case the solution provider has used an open-source or third-party software codes/ libraries in
building the offered software, then they should ensure such components are secured by design. In
addition, solution provider should share the Software Bill of Materials (SBOM) for all open-source
components with BPCL.
77. The solution provider must conduct all necessary checks to ensure that any open-source or third-party
software codes/ libraries used in building the offered software does not have any embedded security
threat such as malware, rootkit, remote access trojans or backdoor etc.
78. All Internet-facing web applications should have Web Application Firewall (WAF), Anti-DDoS,
Anti-BOT, API security protection enabled.
79. Logging should be enabled at all layers of the infrastructure and logs to be provided for auditing/
forensic investigations as and when requested by BPCL. All security, access & transaction logs
should be retained for minimum 180 days.
80. Change Management process should be followed for making changes in the solution as well as in the
infrastructure.
81. The solution should be governed through continuous monitoring & response (identify-protect-detect-
respond-recover) from any security incident/ data breach.
82. The solution provider should follow secure software development lifecycle practices (including Static
Application Security Testing, source code review, etc.) to develop & maintain the software being
83. Solution shall validate all user inputs appropriately to ensure the input is consistent with the
requirement and follows permitted lengths and formats.
84. Adequate measures shall be taken by the solution provider to ensure that the solution or any of its
components does not have any malware (such as trojan, backdoor, spyware, miner etc.) installed in
it. Solution provider shall provide an assurance letter/undertaking on their letter head to BPCL in this
regard. Commented [jh2]: Is there any format?
85. The solution must implement robust security measures to protect AI models, data and infra from
cyber threats and unauthorized access
86. AI models used in the solution should be protected against various AI-specific attacks such as prompt
injection and adversarial inputs.
87. All communication to the solution and associated APIs should be protected using rate-limiting,
authentication and authorization controls.
88. The Solution should have compartmentalization techniques that have been employed to isolate BPCL
data from other customers’ data. Also, the platform should perform regular backup and recovery tests
to assure that logical segregation and controls are effective.
89. The provider should ensure that no removable media policy or program (CDs, DVDs, tapes, disk
drives) are permissible on their employees’ desktop/laptop/devices. All devices used by the vendor’s
employees to access the platform should have adequate security controls in place and should be
approved by vendor’s management.
90. The solution should have safeguards to protect itself from various attacks including OWASP Top10,
different types of Injection attacks, Cross Site scripting etc.
91. The solution should restrict upload of specific types of files extensions, file size and content type. Eg:
92. The solution should demonstrate sufficient protection against redirection flaws and click-jacking
93. The solution provider must notify BPCL immediately as soon as they know or believe that a Cyber
Security Incident/ Breach of Data/ Loss of Information has or may have taken place and must provide
full details of the incident and any mitigation measures already taken and intended to be taken by
them and (where applicable) any mitigation measures recommended by them to be taken by BPCL.
94. Following a Cyber Security Incident involving BPCL’s services/ data, the solution provider should:
e. use their best endeavours to mitigate the impact of the Cyber Security Incident, e.g. if any
system is reported under breach/ incident, the solution provider should disconnect it from the
network immediately to contain its lateral movement.
f. extend all necessary support and assistance to BPCL for carrying out incident analysis/ forensic
investigation till its conclusion.
g. ensure to preserve the digital evidence and logs till the conclusion of the investigation and
confirmation from BPCL about the deletion of the evidence.
h. take any action deemed necessary by BPCL in the circumstances, including complying with
any additional security measures deemed appropriate by BPCL.
The solution provider shall ensure to comply with the Digital Personal Data Protection Act 2023 and
Aadhaar Act 2016 (if applicable) for storing and processing of all kinds of Digital Personal Data (DPD)
and Sensitive Personal Data or Information (SPDI)
VAPT/ WAPT Report
• Bidder shall submit latest VAPT/ WAPT by CIRT-IN certified agency as per BPCL Standard and all
requirements raised by BPCL during the contract period. The cost towards VAPT/ WAPT and mitigation
of reported vulnerabilities shall be borne by bidder.
Annexure-14 Confirmation on Scope understanding & Deviation Statement
Declaration by bidder on their letter head that they have understood the scope of work & specification and
accept all terms and conditions as details in tender (including all corrigendum) with NIL deviation.
Annexure-15 Payment Terms
The Company, in consideration of the bidder carrying out and executing the said work to the satisfaction of
the company, shall pay to the bidder as per the said schedule of rates, subject to deductions, retentions and
abatements, if any to be made therefrom in accordance with the provisions of this contract. The following shall
be the payments terms:
• Rates quoted including “Price Discovery” section of the price bid shall remain firm during contract
• Half yearly advance payment shall be made within 30 days from the submission of invoice.
• Vendor should submit the invoice as per the purchase order superscribing the Purchase Order No., Item
No. & item Description.
• Bidder should ensure that the invoices are prepared as per provisions of GST Act, with correct Billed
to/from or Shipped to/from, components. Service Provider should get these input cleared by the Digital
Business Procurement Teams before raising any Invoices, so as to avoid any accounting issues later.
• BPCL will release the payment within 30 days of submission of valid invoice subject to the condition
that invoice and all supporting documents produced are in order and work is performed as per the scope
of the project and meeting the SLA criteria. BPCL shall be entitled to delay or withhold the payment of
a disputed invoice or part of it delivered by bidder, when BPCL disputes such invoice or part of it,
provided that such dispute is bona fide.
• BPCL shall not be held responsible for delay in payment under the following circumstances.
o Non-submission of Bank Guarantee as per tender / PO terms & conditions.
o Deviation in billing pattern (like States / HSN/SAC) after placement of PO.
o Delay in submission of bills.
• Payments would be released by our office at BPEC, KHARGHAR through NEFT. The invoice should be
addressed to BPEC.
• In case of any discrepancy between General Purchase Condition (GPC) and Special Purchase Condition,
Special Purchase Condition of shall prevail.
1) Basic price and rate of tax applicable on the material supplied should be separately mentioned in the Tender
Form. Bidder shall be required to indicate the SAC/ HSN Code along with tax rates as applicable under
GST law, in unpriced bid and at the time of quoting.
2) The rates along with taxes shall remain valid for the entire period of contract. However, BPCL shall have
option to review the prices for downward/ upward revision of cost due to reduction/ increase in government
levies, taxes, duties etc.
3) Variation in the rates for Statutory levies/ taxes/ duties during the tenure of the contract for supplies within
delivery schedule will be allowed only on the submission of documentary evidence from Govt./ Statutory
Authorities and its acceptance by BPCL.
4) Any downward revision in taxes or levies etc., during the contract period shall be recovered from the vendor
from the current running bills. Changes in the taxes structure as mentioned above shall be updated in the
5) The price quoted in the Price Bid should cover charges for all Products/ Services asked in this Tender. No
other payment shall be made over and above quoted rates.
6) All prices quoted should be in INR.
Annexure-16 BILLING ADDRESS:
BHARAT PETROLEUM CORPORATION LIMITED
Digital Business, Sewree Fort Road, K Installation,
Sewree – East, Mumbai
BPCL has setup a Business Process Excellence Centre (BPEC) for Vendor Invoice processing. BPEC will
function as a payments factory to receive, digitize and process vendor invoices in a timely and accurate
manner. In addition, the centre will receive and account for Performance Bank Guarantees (PBGs) and Bank
Guarantees (BGs). ORIGINAL COMMERCIAL INVOICES (IN TAX INVOICE FORMAT) will need to be
sent to BPEC including Supporting Documents for Payments.
PLEASE SEND THESE DOCUMENTS TO THE FOLLOWING ADDRESS FOR PAYMENT
BUSINESS PROCESS EXCELLENCE CENTRE (BPEC)
4th FLOOR, BPCL OFFICE COMPLEX
PLOT-6, SECTOR-2, BEHIND CIDCO GARDEN
KHARGHAR, NAVI MUMBAI-410210
MAHARASHTRA, INDIA
Tap a document below to read it instantly. You can also download everything as a ZIP if you prefer.
details.html
RAW_HTML
22597.pdf
pdf • 0.78 MB
BUDGETDOC_22597.pdf
pdf • 0.64 MB
Download all tender documents and submit your bid
Disclaimer: TenderKart has made every reasonable effort to ensure that the information on this page is accurate and authentic, however it cannot be held liable for any third-party claims or losses or any damages. TenderKart makes no warranty, expressed or implied, as to the results obtained from the use of this information. If you notice any error or omission, please let us know at .