7. In terms of Rules 48 of Public Procurement Rules, 2004 Grievance Redressal Committee (GRC) is notified for the subject procurement and notification copy is available on the procuring agency’s website and also available on EPADS v2.0 as well as Authority’s website at (www.ppra.org.pk).
National Disaster Risk Management Fund (National Disaster Risk Management Fund (NDRMF)), Manager
5th Floor, EOBI House, G-10/4., Islamabad Capital Territory
+92-321-400-4044
muhammad.asif@ndrmf.pk
The following specific data for the procurement of Non-Consultancy Services to be procured shall complement, supplement, or amend the provisions in the Instructions to Bidders (ITB). Whenever there is a conflict, the provisions herein shall prevail over those in ITB.
BDS Clause Number
ITB Number
Amendments of, and Supplements to, Clauses in the Instruction to Bidders
BDS Clause Number 1
Name of Procuring Agency: National Disaster Risk Management Fund (National Disaster Risk Management Fund (NDRMF))
The subject of procurement is: Renewal of ThreatHawk SIEM Solution and Support Services for One Year
Expected commencement date: Friday, September 18, 2026
BDS Clause Number 2
Financial year for the operations of the Procuring Agency: 2026-27
Name and identification number of the Contract: P78409
BDS Clause Number 3
JV/Consortium or Association Allowed: No
Number of JV/Consortium Members: Nil
BDS Clause Number 4
The Bidders may seek clarifications through EPADS v2.0: Clarification Date: Monday, August 31, 2026
BDS Clause Number 5
Any addendum, in case issued, shall be published on National Disaster Risk Management Fund (National Disaster Risk Management Fund (NDRMF)) website and on EPADS v2.0.
BDS Clause Number 6
List of documents required along with the bid:
BDS Clause Number 7
The qualification criteria to establish the supply / production capability of the bidder.
see Eligibility Criteria
BDS Clause Number 8
Services and Their related documents:
See section Required Services and Scope of Work
BDS Clause Number 9
Price schedule will be provided according to the format defined and acquired.
see section price schedule.
BDS Clause Number 10
Specifications:
see section of specifications.
BDS Clause Number 11
The price shall be Fixed.
BDS Clause Number 12
Currency of the Bids shall be : PKR
BDS Clause Number 13
The Bids/Bid Validity period shall be: 60 Days
BDS Clause Number 14
The amount of Bid Security shall be as defined in Bid Security Section for items and lots given in BDS 6
The Bid Security shall be in the form of:
BDS Clause Number 15
The Bids security shall be valid for twenty-eight (28) days beyond the expiry of the Bids validity period specified in the bidding documents, for example the bid validity is 90 days so the bid security shall be valid for 90+28 = 118 days.
BDS Clause Number 16
Alternative Bids to the requirements of the bidding documents will not be permitted.
BDS Clause Number 17
Bid shall be submitted online on EPADS v2.0 whereas hard copy of the bid security should be submitted to the following;
5th Floor, EOBI House, G-10/4., Islamabad Capital Territory
Bids that are not submitted on EPADS v2.0 shall be disqualified.
The deadline for Bids submission is: Thursday, September 3, 2026 10:00 AM
BDS Clause Number 18
The Bids opening shall take place on EPADS v2.0.
Day : Thursday
Date: Thursday, September 3, 2026
Time : 10:30 AM
BDS Clause Number 19
Selection technique adopted will be: Least Cost Based Selection (LCBS)
see Evaluation Criteria
BDS Clause Number 20
The Performance guarantee shall: 0%.
The Performance Guarantee shall be acceptable in the form of: Nil
21.
51.1
Arbitrator shall be appointed by mutual consent of the both parties.
BDS Clause Number 22
Grievence against this procurement shall be submitted online on EPADS v2.0.
| Bidder's Type | Required Registration |
|---|---|
|
Sole Proprietorship Partnership Firm Company (Private Limited) Company (Public Limited) Company (Holding Company) Company (Limited by Guarantee) State Owned Enterprise (Private Limited) State Owned Enterprise (Public Limited) |
FBR (NTN) FBR (GSTN) |
| Eligibility Criteria | Document |
|---|---|
| a. Bidder must be registered with Income & sales Tax Departments and on ATL status, [shall be attached with the e-bid(s)] | Yes |
| b. Bidder must have proper Business Location/setup, telephone facility and established support mechanism, [proof shall be attached with the e-bid(s)]. | Yes |
| c. Bidders must provide an undertaking on company letterhead that bidder is not blacklisted by any public sector organization, [shall be attached with the e-bid(s)] | Yes |
| d. The bidder must have experience of successful deployment of at least three (03) recognized security solutions. [Documentary proof of supply orders/contracts, completion certificate(s) to establish the required experience, shall be attached with the e-bid(s)] | Yes |
| e. Bidders are required to submit a duly signed and stamped Technical Compliance Sheet. | Yes |
| f. Bidders will provide the Manufacturer Authority Letter (MAL) from OEM [shall be attached with the e-bid(s)]. | Yes |
| g. Bidder/OEM must have local presence in Pakistan [Proof must be attached with e-bid(s)] | Yes |
Least Cost Based Selection (LCBS)
No
Positions Without Lots :
Position: Renewal of ThreatHawk SIEM Solution and Support Services for One Year
Specifications / Requirements:
Scope of Services: Renewal of SIEM Solution License & Support Services 1. Background A Security Information and Event Management (SIEM) solution is a centralized cybersecurity platform used to collect, monitor, analyze, and correlate logs and security events generated by network devices, servers, firewalls, applications, databases, and endpoints. It helps an organization detect suspicious activities, cyberattacks, unauthorized access attempts, system vulnerabilities, and operational issues from a single monitoring platform. The SIEM solution namely, “ThreatHawk SIEM Solution, is currently deployed at the NatCat Data Center is working effectively and is successfully collecting logs from the connected devices and systems. It provides centralized visibility of security events, real-time monitoring, alerts, reporting, threat detection, compliance monitoring, and incident investigation. The solution has supported the NatCat Center in improving its security posture and ensuring continuous monitoring of its IT infrastructure. To continue these essential cybersecurity monitoring and threat-detection services without interruption, renewal of the existing SIEM solution license is required for the next one year, along with support services for said period. 2. Requirements “Renewal of ThreatHawk SIEM Solution and Support Services for one year" 2.1 Feature Requirements The solution must be compliant to the attached Compliance Sheet in the Bidding Document. 3. Duration: One YearScope of Services: Renewal of SIEM Solution License & Support Services
A Security Information and Event Management (SIEM) solution is a centralized cybersecurity platform used to collect, monitor, analyze, and correlate logs and security events generated by network devices, servers, firewalls, applications, databases, and endpoints. It helps an organization detect suspicious activities, cyberattacks, unauthorized access attempts, system vulnerabilities, and operational issues from a single monitoring platform.
The SIEM solution namely, “ThreatHawk SIEM Solution, is currently deployed at the NatCat Data Center is working effectively and is successfully collecting logs from the connected devices and systems. It provides centralized visibility of security events, real-time monitoring, alerts, reporting, threat detection, compliance monitoring, and incident investigation. The solution has supported the NatCat Center in improving its security posture and ensuring continuous monitoring of its IT infrastructure.
To continue these essential cybersecurity monitoring and threat-detection services without interruption, renewal of the existing SIEM solution license is required for the next one year, along with support services for said period.
2. Requirements
“Renewal of ThreatHawk SIEM Solution and Support Services for one year"
Â
2.1. Feature Requirements
The solution must be compliant to the following features:
|
Sr # |
SIEM Solution Technical/Functional Requirement  |
Required Compliance |
|
Instant Search: Applies instant multi-level filtering to filtered data. |
 |
|
2 |
Raw Logs for Advance Searching |
 |
|
3 |
It will provide Agent Details (Network Interfaces, Ports, Packages and Processes etc.) |
 |
|
4 |
Remote Agent Deployment from SIEM |
 |
|
5 |
Windows Event ID Tuning and Configuration - Group Based Event Tuning |
 |
|
6 |
Rule Tuning to capture new attackers and/or optimization |
 |
|
7 |
Data Retention and Index Health Management |
 |
|
8 |
Theme Customizer - User can switch Theme of application i.e. light & dark |
 |
|
9 |
User Groups to categorize users based on roles, department, or duties. |
 |
|
10 |
Audit Logs to capture all actions of users |
 |
|
11 |
Auto Asset Discovery for identification of Unknown Devices |
 |
|
12 |
The platform must support manual backups as well as automated, time-based backups for data integrity and continuity. |
 |
|
13 |
Compliance Module (NIST, HIPAA, PCI DSS, GDPR, ISO, SOC 2, ADSIC, CIS and NESA) |
 |
|
14 |
CIS-CAT and Open SCAP integration (CIS Benchmarking) |
 |
|
15 |
Compliance count in respective dashboard |
 |
|
16 |
ISO-27001 Compliance |
 |
|
17 |
Customizable Visualization Module |
 |
|
18 |
Agent and Agentless dashboards |
 |
|
19 |
Threat detection through MAP visualization along with attacking IPs |
 |
|
20 |
Map chart integration in custom visualization |
 |
|
21 |
Provision for customizable dashboard creation as per user profiles/privileges. |
 |
|
22 |
No-Code Custom Dashboards |
 |
|
23 |
Custom Queries based Dashboarding |
 |
|
24 |
The platform must support on-demand generation of customized reports tailored to specific user requirements. |
 |
|
25 |
The platform must support scheduled generation of customized reports at predefined intervals or times. |
 |
|
26 |
The platform must support query-based generation of customized reports, allowing users to dynamically extract data. |
 |
|
27 |
Desktop App for Windows |
 |
|
28 |
USB Detection Logs in the Network |
 |
|
29 |
SMTP Configuration |
 |
|
30 |
SNMP Traps and Device NetFlow |
 |
|
31 |
Slack and Telegram Integration |
 |
|
32 |
Integration of SAP ERP logs and Custom Dashboards |
 |
|
33 |
Cloud, Hybrid and on-prem deployment is supported. |
 |
|
34 |
Cloud Integration with AWS, GCP and Azure |
 |
|
35 |
Organization Risk Score or Security Posture or Internal Attack Surface Management dashboards. |
 |
|
36 |
Email Alert Reporting with respect to Alert Severity |
 |
|
37 |
Configure Email Alerts with Severity Level |
 |
|
38 |
Notifications (In-App, via Mobile Apps, Email) |
 |
|
39 |
In-App and Off-App releases must be available for SIEM |
 |
|
40 |
Reports can be scheduled over different intervals. |
 |
|
41 |
Reporting Module with CSV and PDF Reports |
 |
|
42 |
Report Customization Module |
 |
|
43 |
Automated reporting for various compliance standards, including ISO-27001, GDPR, HIPAA, PCI-DSS, and more |
 |
|
44 |
PDF report download support for all tables |
 |
|
45 |
Device Risk Score must be assigned to all devices (Endpoints, Firewall, Router and Switch) |
 |
|
46 |
Task Management, Status and Priority can be added against each alert, Vulnerability |
 |
|
47 |
GeoIP Location Tracking |
 |
|
48 |
Threat Intel 1 – Abuse IP DB |
 |
|
49 |
Threat Intel 2 - Abuse Finder |
 |
|
50 |
Threat Intel 3 – Cyber Protect Threat Score |
 |
|
51 |
Threat Intel 4 - DNS Looking Glass |
 |
|
52 |
Threat Intel 5 – DShield |
 |
|
53 |
Threat Intel 6 - Echo Trail |
 |
|
54 |
Threat Intel 7 - Google Safe Browsing |
 |
|
55 |
Threat Intel 8 - IP-API |
 |
|
56 |
Threat Intel 9 - IP info |
 |
|
57 |
Threat Intel 10- MISP |
 |
|
58 |
Threat Intel 11 - Malware Bazaar |
 |
|
59 |
Threat Intel 12 - Alien Vault |
 |
|
60 |
Threat Intel 13 - Phishing Initiative |
 |
|
61 |
Threat Intel 14 - Stop Forum Spam |
 |
|
62 |
Threat Intel 15 - Team Cymru |
 |
|
63 |
Threat Intel 16 - Threat Miner |
 |
|
64 |
Threat Intel 17 - URLhaus |
 |
|
65 |
Threat Intel 18 - URL Scan IO Scan |
 |
|
66 |
Threat Intel 19 - URL Scan IO Search |
 |
|
67 |
Threat Intel 20 - VirusTotal |
 |
|
68 |
Threat Intel 21 - OpenCTI |
 |
|
69 |
MITRE Tactics and Techniques Mapping with Alerts |
 |
|
70 |
Threat Intelligence for IP, Hash, URL and Domain |
 |
|
71 |
Collective Threat Score and IOC Score for each IOC |
 |
|
72 |
Assigning IOCs to User |
 |
|
73 |
APT group information in SIEM |
 |
|
74 |
File Activity Monitoring Module to observe all CRUD activities |
 |
|
75 |
Vulnerability Detection for Network Devices (Firewall, Router, Switches etc.) |
 |
|
76 |
The platform must generate a report to mention vulnerabilities whose patches are available along with a fixed version for that package and OS. |
 |
|
77 |
The platform must generate consolidated reports identifying hosts that require specific patches. |
 |
|
78 |
SIEM must collect and process logs from various sources, including routers, switches, servers, firewalls, IDS/IPS, applications, databases, and endpoints. |
 |
|
79 |
Advanced correlation capabilities for detecting complex attacks or suspicious activities. |
 |
Â
3. Duration: One Year
For Individual Positions
| # | Position Title | Quantity | Unit Price (PKR) | Total Price (PKR) | Delivery Location | Delivery Period / Year | Country of Origin |
|---|---|---|---|---|---|---|---|
| 1 | |||||||
| 2 |
| # | Lot Title | Total Lot Price (PKR) | Country of Origin |
|---|---|---|---|
| 1 | [Lot 1 Title] |
The following Special Conditions of Contract shall supplement the General Conditions of Contract. Whenever there is a conflict, the provisions herein shall prevail over those in the Conditions of Contract. The corresponding clause number of the GCC is indicated in parentheses.
Number of GC Clause
Amendments of, and Supplements to, Clauses in the General Conditions of Contract
Definitions
The Procuring Agency is: National Disaster Risk Management Fund (National Disaster Risk Management Fund (NDRMF)), Manager 5th Floor, EOBI House, G-10/4., Islamabad Capital Territory
The Supplier is:
The title of the subject procurement is:Renewal of ThreatHawk SIEM Solution and Support Services for One Year
Number of GC Clause 2
Applicable/Governing Law:
The Contract shall be interpreted in accordance with the laws of Islamic Republic of Pakistan
Number of GC Clause 3
Language:
The language of the Contract, all correspondence and communications to be given, and all other documentation to be prepared and supplied under the Contract shall be in English.
Number of GC Clause 4
Notices:
The addresses for the notices are:
Procuring Agency:
National Disaster Risk Management Fund (National Disaster Risk Management Fund (NDRMF)), Manager
5th Floor, EOBI House, G-10/4., Islamabad Capital Territory
+92-321-400-4044
muhammad.asif@ndrmf.pk
Contractor/ Bidder:
[Name, address and telephone number].
The Contractor/ Bidder’s Representative(s)
[Name, address, telephone number and e-mail address]
Number of GC Clause 6.1
The Authorized Representatives are:
For the Procuring Agency:
National Disaster Risk Management Fund (National Disaster Risk Management Fund (NDRMF)), Manager
5th Floor, EOBI House, G-10/4., Islamabad Capital Territory
+92-321-400-4044
muhammad.asif@ndrmf.pk
For the Bidder:
Name: ………………………
Designation: ……………..
Address: ……………………………..
Number of GC Clause 7
Effectiveness of the contract
The Contractor/Bidder shall be effective within ….. days from the date of signature of the Contract by both parties
Number of GC Clause 8
Commencement of Contract:
The Contractor/ Bidder shall provide Non-Consultancy Services from the effective date of contract.
Number of GC Clause 10.2
Expiration of Contract:
The time period shall be ………………….
Number of GC Clause 14
Termination
In the event of termination of the contract due to any reason as already defined in the General Conditions of Contract, the Bidder shall be responsible for providing to the Authority the Services till the time of alternate arrangements.
Number of GC Clause 16
Conflict of Interest:
The Procuring Agency reserves the right to determine on a case-by-case basis whether the Bidder should be disqualified from providing services due to a conflict of a nature described in Clause GCC C2.
Number of GC Clause 20
Liquidated Damages
If the Bidder fails to provide services as required under the contract or in case of any data loss/data breach or any incident compromising the data security or other such failures related to any services, the Bidder shall pay to the Procuring Agency as Liquidated Damages at a rate of 0.10% to 5.00% of the Contract value, in accordance with the extent of performance failure & the cost of investigating such incidents as judged by the Authority.
Number of GC Clause 21
Performance Guarantee:
The amount of performance guarantee shall be 0% of the contract price in acceptable form of Nil
Number of GC Clause 27
Currency of Payment:
All the payment to be released to the contractor/Bidder shall be in Pakistani Rupees.
Number of GC Clause F
Payment terms:
Payment will be made to the Bidder against the procured Goods and services according to the actual invoice or running bills submitted by the Bidder against the services provided within the time given in the conditions of the contract.
Number of GC Clause F
Identifying Defects:
The Authority reserves the right at any time to inspect the premises of the provider to inspect the goods and monitor the goods being provided.
For successful operation at site after complete installation, testing and commissioning of the equipment (Installation, Testing and Commissioning Report by Procurement Committee / Inspection Team)
Copies of the Supplier’s invoice showing Goods’ description, quantity, unit price, and total amount;
Number of GC Clause F 5 & 6
Following is the guidance for Dispute Resolution
Notwithstanding any reference to the arbitration herein, the parties shall continue to perform their respective obligations under the Contract unless they otherwise agree that the Authority shall pay the Bidder any monies due to the Bidder.
Arbitrator’s fee:
The fee shall be specified in Pak Rupees, as determined by the Arbitrator, which shall be shared equally by both parties.
Appointing Authority for Arbitrator:
By the Mutual Consent or in accordance with the provisions of Arbitration Act, 1940, in case the parties fail to reach a consensus on the name of sole arbitrator, any party may submit an application to the Chief Justice Islamabad High Court for appointment of sole arbitrator. The Chief Justice IHC may appoint a former judge of any High Court or Supreme Court as the sole arbitrator to resolve the dispute between the parties.
Rules of procedure for arbitration proceedings:
Any dispute between the Authority and a Bidder who is a national of the Islamic Republic of Pakistan arising in connection with the present Contract shall be referred to adjudication or arbitration in accordance with the laws of the Islamic Republic of Pakistan including Arbitration Act 1940, however above provision shall prevail in referring the case to the Arbitrator.
Place of Arbitration and Award:
The arbitration shall be conducted in English language and place of arbitration shall be at Islamabad. The award of the arbitrator shall be final and shall be binding on the parties.
Date: [insert date (as day, month and year)]
Bid No.:P78409
To: National Disaster Risk Management Fund (National Disaster Risk Management Fund (NDRMF)), Manager 5th Floor, EOBI House, G-10/4., Islamabad Capital Territory
We, the undersigned, declare that:
We understand that, according to your conditions, Bids must be supported by a Bid Securing Declaration.
We accept that we will be blacklisted and henceforth cross debarred for participating in respective category of public procurement proceedings for a period of (not more than) six months, if fail to abide with a bid securing declaration, however without indulging in corrupt and fraudulent practices, if we are in breach of our obligation(s) under the Bid conditions, because we:
We understand this Bid Securing Declaration shall expire if we are not the successful
Bidder, upon the earlier of (i) our receipt of your notification to us of the name of the successful Bidder; or (ii) twenty-eight (28) days after the expiration of our Bid.
THIS AGREEMENT made the _____ day of __________ 20_____ between National Disaster Risk Management Fund (National Disaster Risk Management Fund (NDRMF)), Manager 5th Floor, EOBI House, G-10/4., Islamabad Capital Territory
(hereinafter called “the Procuring Agency”) of the one part and [name of Bidder] of [city and country of Bidder] (hereinafter called “the Bidder”) of the other part:
WHEREAS the Procuring Agency invited Bids for provision of goods, viz., Renewal of ThreatHawk SIEM Solution and Support Services for One Year (P78409) and has accepted a Bids by the Bidder for the provision of Goods in the sum of [contract price in words and figures] (hereinafter called “the Contract Price”).
NOW THIS CONTRACT WITNESSETH AS FOLLOWS:
1. In this Contract words and expressions shall have the same meanings as are respectively assigned to them in the Conditions of Contract referred to.
2. The following documents shall be deemed to form and be read and construed as part of this Contract, In the event of any ambiguity or conflict between the Contract Documents listed below, the order of precedence shall be the order in which the Contract Documents are listed below:-
3. In consideration of the payments to be made by the Procuring Agency to the Bidder as hereinafter mentioned, the Bidder hereby covenants with the Procuring Agency to provide the Goods related services and to remedy defects therein in conformity in all respects with the provisions of the Contract.
4. The Procuring Agency hereby covenants to pay the Bidder in consideration of the provision of Goods and the remedying of defects therein, the Contract Price or such other sum as may become payable under the provisions of the contract at the times and in the manner prescribed by the contract.
IN WITNESS whereof the parties hereto have caused this Contract to be executed in accordance with their respective laws the day and year first above written.
Signed, sealed, delivered by __________________the ________________ (for the Procuring Agency)
Witness to the signatures of the Procuring Agency:
………………………………………………
Signed, sealed, delivered by __________________the ________________ (for the Procuring Agency)
Witness to the signatures of the Bidder: …………………………………………………
Contract Number: Contract Value: Contract Title:
Dated:
[Name of Supplier] hereby declares that it has not obtained or induced the procurement of any contract, right, interest, privilege or other obligation or benefit from Government of Pakistan or any administrative subdivision or agency thereof or any other entity owned or controlled by it (GoP) through any corrupt business practice.
Without limiting the generality of the foregoing [Name of Supplier] represents and warrants that it has fully declared the brokerage, commission, fee etc. paid or payable to anyone and not given or agreed to give and shall not give or agree to give to anyone within or outside Pakistan either directly or indirectly through any natural or juridical person, including its affiliate, agent, associate, broker, consultant, director, promoter, shareholder, sponsor or subsidiary, any commission, gratification, bribe, finder's fee or kickback, whether described as consultations fee or otherwise, with the object of obtaining or inducing the procurement of a contract, right, interest, privilege or other obligation or benefit in whatsoever form from GoP, except that which has been expressly declared pursuant hereto.
[Name of Supplier] certifies that it has made and will make full disclosure of all agreements and arrangements with all persons in respect of or related to the transaction with GoP and has not taken any action or will not take any action to circumvent the above declaration, representative or warranty.
[Name of Supplier] accepts full responsibility and strict liability for making and false declaration, not making full disclosure, misrepresenting fact or taking any action likely to defeat the purpose of this declaration, representation and warranty. It agrees that any contract, right interest, privilege or other obligation or benefit obtained or procured as aforesaid shall, without prejudice to any other right and remedies available to GoP under any law, contract or other instrument, be voidable at the option of GoP.
Notwithstanding any rights and remedies exercised by GoP in this regard, [Name of Supplier] agrees to indemnify GoP for any loss or damage incurred by it on account of its corrupt business practices and further pay compensation to GoP in an amount equivalent to ten time the sum of any commission, gratification, bribe, finder's fee or kickback given by [Name of Supplier] as aforesaid for the purpose of obtaining or inducing the procurement of any contract, right, interest, privilege or other obligation or benefit in whatsoever form from GoP.
To: National Disaster Risk Management Fund (National Disaster Risk Management Fund (NDRMF)), Manager 5th Floor, EOBI House, G-10/4., Islamabad Capital Territory
WHEREAS [name of Bidder] (hereinafter called “the Bidder”) has undertaken, in pursuance of Contract No. [reference number of the contract] dated [insert date] for provision of Goods(hereinafter called “the Contract”).
AND WHEREAS it has been stipulated by you in the said Contract that the Bidder shall furnish you with a Bank Guarantee by a reputable bank for the sum specified therein as security for compliance with the Bidder’s performance obligations in accordance with the Contract.
AND WHEREAS we have agreed to give the Bidders guarantee:
THEREFORE, WE hereby affirm that we are Guarantors and responsible to you, on behalf of the Bidder, up to a total of [amount of the guarantee in words and figures], and we undertake to pay you, upon your first written demand declaring the Bidder to be in default under the Contract and without cavil or argument, any sum or sums within the limits of [amount of guarantee] as aforesaid, without your needing to prove or to show grounds or reasons for your demand or the sum specified therein.
This guarantee is valid until the: [insert date]
Signature and seal of the Guarantors
_____________________________________________________________________
[name of bank or financial institution]
_____________________________________________________________________
[address]
_____________________________________________________________________
[date}
Attached
Attached
Attached
Attached