Hiring of Vulnerability Assessment and Penetration Testing Services
📌 Tender No: P24350
Active Tender
⏰ Closing Date:
2026-05-21
2026-05-21
Tender Overview
- 📂 Category
- IT Services & Support
- 🏭 Sector
- Services
- 📄 Tender Type
- Services
- ⚙️ Procurement Method
- Open Competitive Bidding
- 📨 Submission Method
- Electronic Submission via EPADS v2.0
- 🌐 Source Name
- PPRA
Location & Dates
- 📍 City
- Islamabad
- 🗺️ Province
- Islamabad Capital Territory
- 🌍 Country
- Pakistan
- 📅 Publish Date
- 2026-05-11
- ⏳ Closing Date
- 2026-05-21
- 🕒 Created At
- 2026-05-11 06:17:59
Contact & Websites
- 👤 Contact Person
- Manager
- 📞 Contact Phone
- +92-321-400-4044
- ✉️ Contact Email
- muhammad.asif@ndrmf.pk
- 🌐 Website
- https://vendors.epads.gov.pk/
- 🔗 Original Source
- https://vendors.epads.gov.pk/
Actions
📥 Download Tender Document
🔗 View Original Advertisement
⬅️ Back to All Tenders
Looking for more tenders like this? View all active IT Services & Support tenders.
Related Tenders
Supply Installation Commissioning of IT Networking Infrastructure and Equipment
Close: 2026-06-04 Peshawar, Khyber Pakhtunkhwa
Supply, Installation and Commissioning of Integrated Cyber Security Solution with SOC Establishment
Close: 2026-06-04 Karachi, Sindh
Renewal of CSI Agreement of EXADATA X10M and ZDLRA Systems
Close: 2026-06-08 Islamabad, Islamabad Capital Territory
Repair and Maintenance of IT Equipment (Server, Workstations and Desktop Computers) of...
Close: 2026-06-04 Lahore, Punjab
Repair and Maintenance of Computers, Printers, Networking Equipment and Accessories
Close: 2026-06-05 Lahore, Punjab
Establishment of Mini AI Data Centre (Imported)
Close: 2026-06-05 Rawalpindi, Punjab
Tender Document
Tender Description
The National Disaster Risk Management Fund (NDRMF) based in Islamabad Capital Territory is procuring specialized Vulnerability Assessment and Penetration Testing (VAPT) services to evaluate and enhance the security posture of its IT infrastructure. This procurement is specifically for conducting comprehensive security testing across NDRMF's primary and secondary data centers located in Islamabad, including network devices, servers, web applications, email servers, and endpoints.
The technical scope includes external and internal network infrastructure assessment, web and mobile application testing, server and database security evaluation, and testing of firewalls, routers, switches, and wireless networks. The service provider must follow a structured VAPT methodology covering reconnaissance, vulnerability scanning, manual verification, controlled exploitation, post-exploitation, and detailed reporting with recommendations. Testing will be hybrid, combining online and on-premises modes.
Eligible bidders must be registered with FBR and on ATL status, possess a valid business setup with telephone facilities, and must not be blacklisted. Experience criteria include at least three successful IT service contracts in the last five years and a minimum of three certified professionals holding certifications such as OSCP, CEH, CISSP, or equivalent. ISO 27001 certification is mandatory. Bidders must also submit a detailed work plan and methodology for the assignment.
The submission deadline is **May 21, 2026, at 10:00 AM** through the EPADS v2.0 portal. Manual bids will not be accepted. The technical and financial bids will be evaluated using Least Cost Based Selection (LCBS). The bid security and performance guarantee requirements are clearly defined in the bidding documents. Bidders should ensure timely submission of original bid security to avoid disqualification.
A practical tip for bidders is to carefully review the detailed scope and ensure all required certifications and documentary proofs are attached with the proposal. Early registration on EPADS v2.0 and familiarization with the e-bidding process will help avoid last-minute technical issues. The contract duration is within 90 days following signing, with full payment upon acceptance of deliverables. This is a critical opportunity for cybersecurity firms to engage with a federal agency and demonstrate their expertise in securing vital government infrastructure.
