WhatsApp Chat
🎁 New Users: 7 DAYS FREE TRIAL — Koi Payment Nahi, Full Access! 🚀 Free Account Banayein

IT Cybersecurity Audit and NEPRA Compliance for LESCO Primary and Disaster Recovery Data Centers

Tender No: 4424
Active Tender
Closing Date:
2026-08-03

Tender Overview

Category
Consultancy Services
Sector
Consultancy
Tender Type
Consultancy
Procurement Method
Open Competitive Bidding
Submission Method
Electronic via EPADS v2.0
Source Name
PPRA

Location & Dates

City
Lahore
Province
Punjab
Country
Pakistan
Publish Date
2026-07-23
Closing Date
2026-08-03
Created At
2026-07-23 07:13:03

Contact & Websites

Contact Person
Chief Engineer
Contact Phone
+92-370-499-0342
Contact Email
ammm5@lesco.gov.pk
Website
https://epads.gov.pk/opportunities/federal/procurements/55091
Original Source
https://epads.gov.pk/opportunities/federal/procurements/55091

Tender Document

Tender Description

The Lahore Electric Supply Company (Material Management) in Lahore is procuring consultancy services for a comprehensive IT Cybersecurity Audit and NEPRA Compliance assessment for its Primary Data Center (PR) and Disaster Recovery Data Center (DR). This procurement is under Tender No 4424 and aims to ensure compliance with NEPRA regulations and the Pakistan Information Security Framework (PISF) 2025. Items being procured: - IT Cybersecurity Audit & NEPRA Compliance for LESCO Primary Data Center (PR) - IT Cybersecurity Audit & NEPRA Compliance for Disaster Recovery Data Center (DR) The scope includes a detailed evidence-based audit covering document review, stakeholder interviews, configuration reviews, control testing, vulnerability assessments, and validation of actual practices. Key areas include governance and cybersecurity management controls, asset management, risk assessment, security awareness, system and communication protection, identity and access management, threat monitoring, incident response, infrastructure security, application security, vulnerability management, and third-party risk controls. The audit will cover network devices, servers, databases, backup and restoration processes, physical and environmental controls, and compliance mapping against NEPRA and PISF standards. Eligibility criteria require bidders to be Category-1 PKCERT/NCERT accredited firms with ISO-17021 certification, registered with FBR and PRA, and have at least five years of relevant experience in cybersecurity risk assessments and IT audits. Financial health and client references must be provided. JV or subcontracting is not allowed unless explicitly permitted. The consultancy must ensure non-disruptive audit activities and data confidentiality. The tender is open for submission through EPADS v2.0 until Monday, August 3, 2026, at 10:30 AM, with bid opening at 11:00 AM the same day. Bidders must submit a bid security and comply with all documentation requirements. The contract duration is 90 days from award. A practical tip for bidders: Ensure your proposal includes a detailed project methodology, compliance approach, and named certified experts with relevant credentials such as ISO 27001 LA/LI, CISA, CISM, CISSP, CEH, OSCP, or CHFI to maximize technical evaluation scores. Early registration on EPADS v2.0 and thorough compliance with bid submission instructions will avoid disqualification.
🔒

Full Tender Details for Subscribers

Subscribe to unlock complete information for every tender on Daily Tender Alert.

  • Issuing Authority & Tender No.
  • Estimated Cost & Budget
  • Procurement & Submission Method
  • Official Contact & Website
  • Download Tender Document (PDF)
  • Full Tender Description & Pro-Tips
  • Category-wise Email & WhatsApp Alerts
  • Province-wise & City-wise Alerts
  • Daily WhatsApp Group Access
7 Days Free Account Banayein View Plans & Subscribe
Scroll to Top