Skip to main content
Information Technology

Compliance Checklist for ICT Government Tenders in South Africa

Avoid disqualification with our technical compliance checklist for IT bids. From OEM authorizations to POPIA and ISO standards.

Compliance Checklist for ICT Government Tenders in South Africa

Government ICT

tenders are notoriously complex. Because technology changes rapidly and security is of paramount importance, the evaluation criteria for IT bids are often significantly more technical than for general supply contracts. To ensure your bid actually reaches the final evaluation stage, rather than being eliminated on a technicality, use this comprehensive compliance checklist tailored to the South African public sector.

1. OEM Authorizations: Proof of Partnership

If you are selling hardware or proprietary software from vendors such as Microsoft, Cisco, or Dell, you must provide a current Original Equipment Manufacturer (OEM) authorization letter. This document proves you are an authorised partner and that government will receive genuine products with valid support and warranty backing, rather than grey-market or unsupported goods.

  • Check that the letter is addressed to your company specifically, not to a generic distributor you happen to resell through.
  • Ensure the letter is genuinely current and not stale relative to the requirements stated in the tender.
  • Verify that your partner tier or accreditation level actually matches what the tender requires, rather than assuming any partnership status is sufficient.

2. Data Privacy and POPIA Compliance

With the Protection of Personal Information Act (POPIA) now fully in force, any IT software or database tender will require you to demonstrate how your company handles personal information, both in the solution you are proposing and in your own internal operations.

  • Information Officer: Proof that your company has registered an Information Officer with the Information Regulator, as required under POPIA.
  • Data Protection Policy: A documented policy outlining how you encrypt, store, and delete personal data, and how you would respond to a data breach.

3. ICASA Licensing (for Networking Tenders)

For tenders involving network infrastructure, fibre, or VoIP services, you must provide proof of the applicable ICASA licence category before your bid can be considered compliant.

  • ECS (Electronic Communications
    Service):
    Required for providing internet and voice services to the client.
  • ECNS (Electronic Communications
    Network Service):
    Required for building
    or operating physical network infrastructure.

4. Security Standards (ISO 27001)

For cloud-based or high-security data projects, ISO 27001 certification is increasingly treated as a standard pre-qualification hurdle. If you don't hold the certificate, make sure your own Information Security Policy is genuinely robust and clearly aligned with recognised international best practice, since evaluators reviewing a bid without formal certification will look closely at what you can demonstrate instead.

5. Staff Certifications and Technical Bench Strength

Beyond company-level accreditation, most technical ICT tenders also evaluate the qualifications of the specific individuals who will actually deliver the project. Collate current copies of relevant vendor and industry certifications for your proposed project team, and be prepared to demonstrate that the named individuals are genuinely available for the contract, not simply listed on paper to strengthen the bid. Departments have become increasingly alert to bids that list highly qualified staff who are never actually deployed on the resulting project, and this mismatch can damage your reputation for future opportunities even if it does not disqualify the current bid.

6. B-BBEE and General Compliance Documents

Alongside the ICT-specific requirements above, standard public sector compliance documents still apply in full. Registration on the Central Supplier Database, a valid SARS tax compliance status, and a current B-BBEE certificate or sworn affidavit for smaller entities all need to be in order. Because B-BBEE level directly affects both your preference points and, on many ICT tenders, your eligibility for certain set-aside categories, keeping this certificate current should be treated as an ongoing administrative priority rather than something addressed only when a specific tender deadline is looming.

ICT Compliance Quick Checklist

RequirementWhy it's CrucialCheck Before Submitting
OEM LetterAuthenticity and vendor supportIs it signed, current, and on the OEM's letterhead?
POPIA StatementLegal compliance for personal dataDoes it clearly address data handling and storage practices?
SITA AccreditationRequired by many departmentsIs your registration active for the relevant category?
Staff CertificationsProves genuine technical bench strengthAre the certificates current and the named staff actually available?
B-BBEE CertificatePoints and transformation credentialsIs your certificate current and correctly reflects your level?

Common Mistakes to Avoid

  • Submitting stale OEM letters: A letter that predates the tender's stated validity requirement is treated as if it does not exist.
  • Generic security policies: A one-page security statement that does not address the specific risks of the proposed solution rarely satisfies evaluators looking for genuine substance.
  • Overlooking subcontractor compliance: If you subcontract any part of the technical delivery, that subcontractor's compliance documents matter too, not just your own.
  • Listing unavailable staff: Naming highly qualified individuals in your bid who are not genuinely committed to the project undermines your credibility if discovered.

Frequently Asked Questions

  • Is an OEM authorization letter always required? Only when you are proposing branded hardware or licensed proprietary software; professional services or custom development tenders may not require one.
  • Do I need ISO 27001 to bid on IT tenders? Not universally, but it is increasingly used as a pre-qualification or scoring factor for cloud-based and high-security projects.
  • What happens if my B-BBEE certificate expires mid-process? It is generally treated as if you do not have one, which can cost you preference points or lead to disqualification.
  • Do all networking tenders require an ICASA licence? Only those involving network infrastructure or communications services; confirm this against the specific scope of work.

Building a Standing Compliance File

Given how many separate documents an ICT tender can require, from OEM letters to security policies to individual staff certifications, the most effective long-term approach is to maintain a single, continuously updated compliance file rather than assembling everything fresh for each opportunity. Assign responsibility for tracking expiry dates on your key certificates and licences to a specific person within your business, and review the file on a fixed schedule, such as quarterly, rather than only when a tender deadline forces the issue. Businesses that treat compliance as an ongoing discipline consistently respond faster to short-notice opportunities than those who only think about it once a specific RFP lands in their inbox.

Working With Subcontractors and Delivery Partners

Many ICT bids are strengthened by bringing in a subcontractor or delivery partner with complementary skills, whether that is a cybersecurity specialist, a niche software developer, or a company with an ICASA licence you do not hold. When you do this, remember that the procuring department will generally expect visibility into that partner's compliance status too, not just your own. Build subcontractor compliance verification into your own bid preparation checklist, and secure their supporting documents well ahead of the submission deadline, since a partner's late or incomplete paperwork can undermine an otherwise strong joint bid. A clear written agreement setting out each party's responsibilities and compliance obligations before you submit also protects both sides if questions arise during evaluation or delivery.

Conclusion

Compliance in ICT

tendering is fundamentally about protecting the state from technical failure and data breaches. By ensuring your OEM relationships are properly documented, your data policies are genuinely POPIA-compliant, and your technical licences and staff certifications are current, you eliminate the majority of avoidable reasons for disqualification. Use this checklist as your final sanity check before sealing your next IT bid, and treat the underlying compliance work as ongoing rather than something you scramble to assemble each time a new opportunity appears.

Tags

ICT ComplianceIT TendersPOPIAISO 27001Checklist
Relevant Tender Opportunities

Based on this article's topics, here are some current tenders that might interest you

Activities of Head Offices; Management Consultancy Activities

Request for information from reputable entities with experience to submit possible solutions on alternative water sources of potable water

City of Tshwane
Gauteng
30 Oct 2026
38d left
Activities of Head Offices; Management Consultancy Activities

Tender for the appointment of a panel of suppliers for supplying and delivering library information resources including (audio visuals) for new and existing libraries as and when required, for a period of three years

City of Tshwane
Gauteng
22 Oct 2026
30d left
Other Professional, Scientific and Technical Activities

Request For Information (RFI) CSIR is requesting information from interested service providers, product suppliers, research organisations and technology developers on: Radio Frequency Electronic Warfare (EW) payloads for unmanned airborne and spaceborne platforms

Council for Scientific and Industrial Research (CSIR)
Gauteng
30 Sept 2026
8d left
Services: Functional (including Cleaning and Security Services)

PROVISION OF CLEANING SERVICES FOR THE NELSON MANDELA MUSEUM AT BHUNGA BUILDING IN MTHATHA, YOUTH AND HERITAGE CENTRE IN QUNU AND INFORMATION CENTRE IN QUNU FOR A PERIOD OF THREE (3) YEARS (RE- ADVERTISED)

Nelson Mandela National Museum
National
14 Oct 2026
22d left
Services: General

Provision of access to the Government Property Information System and related Database for Land Development Cape Coastal Cluster for a period of 5 years on an as and when required basis.

Eskom
Eastern Cape
08 Oct 2026
16d left
Services: Professional

Request for Information for a Forecast Product Generator (FPG) solution

South African Weather Service (SAWS)
Gauteng
07 Oct 2026
15d left

Want to see all available tenders?

Browse All Tenders →
AI-Powered Matching
Never Miss a Perfect Tender Again
Our AI analyzes thousands of tenders and finds the ones YOUR company can actually win
AI Match Scoring for every tender
Instant alerts for 85%+ matches
B-BBEE level optimization
Document readiness checks

Share this article

Compliance Checklist for ICT Government Tenders in South Africa

Avoid disqualification with our technical compliance checklist for IT bids. From OEM authorizations to POPIA and ISO standards.

https://www.tenders-sa.org/blog/ict-tender-compliance-checklist