Launch promo 53% off — full access for R399/month R850
Buy nowThis tender has closed on 14 July 2026.
The information below is kept for reference. Browse active Administrative and support activities tenders or view all open tenders.
Seeking a qualified service provider to conduct a comprehensive cybersecurity maturity assessment, security architecture review, and implement an automated governance, risk, and compliance (GRC) platform for enhanced security posture.
The Passenger Rail Agency of South Africa (PRASA) is inviting proposals from qualified service providers to deliver a robust enterprise cybersecurity maturity assessment and security architecture review. This tender encompasses a variety of critical services, including vulnerability assessments and penetration testing (VAPT), IT/OT integration testing, and the development of a comprehensive cybersecurity strategy and roadmap. Additionally, the successful bidder will implement an automated GRC platform tailored to PRASA’s specific needs, ensuring compliance with various frameworks such as NIST, ISO 27001, and IEC 62443.
The scope of work includes conducting site-level threat and risk assessments, establishing an enterprise cyber risk register, and providing executive dashboards for real-time reporting on maturity, compliance, and risk exposure. The platform must support role-based access, evidence management, and training for PRASA staff to ensure effective operation and governance. Bidders are required to demonstrate relevant experience in cybersecurity assessments, particularly in environments involving operational technology (OT) or industrial control systems (ICS), and provide a detailed methodology for executing the project. This initiative aims to enhance PRASA's cybersecurity resilience and operational integrity in the transport sector.
This tender is suitable for cybersecurity firms with proven experience in enterprise assessments, GRC platform implementation, and those familiar with IT/OT environments. Companies that can demonstrate a strong understanding of regulatory compliance and risk management in critical infrastructure sectors are encouraged to apply.