Ethiopia
ocds-bidanga-ET-OP00456646
Consultancy Services for IT Security Assessment for African Union Commission
Original title: CONSULTANCY SERVICES TO CONDUCT IT SECURITY ASSESSMENT FOR AFRICA UNION COMMISSION
Deadline
July 29, 2026
Key information
- Type
- IT & Telecom
- Location
- Ethiopia
- Deadline
- July 29, 2026 at 12:00 AMClosed
- Estimated Value
- Not disclosed
- Language of Notice
- English
What is this tender about?
Consultancy Services for IT Security Assessment for African Union Commission is an it & telecom procurement opportunity published by Africa Union Commission in Ethiopia on July 14, 2026. Submissions closed on July 29, 2026. 1 official document is attached below.
REQUEST FOR EXPRESSIONS OF INTEREST (CONSULTING SERVICES – FIRM SELECTION) Country: Ethiopia Name of Project: The Building Institutions and Systems to Harness and Realize Agenda (BIASHARA) 2063 Project Grant No: P180117 Assignment Title: Consultancy Services to Conduct IT Security Assessment for Africa Union Commission Reference No. ET-AUC-560866-CS-QCBS The African Union Commission has received financing from the World Bank toward the cost of The Building Institutions and Systems to Harness and Realize Agenda (BIASHARA) 2063 Project and intends to apply part of the proceeds for consulting services.
The consulting services (“the Services”) include conducting a comprehensive penetration testing assessment of the African Union Commission’s ICT infrastructure. The engagement is designed to rigorously evaluate technical controls, identify vulnerabilities, and simulate realistic cyberattack scenarios. The detailed Terms of Reference (TOR) for the assignment are attached to this Request for Expressions of Interest.
The African Union Commission now invites eligible consulting firms (“Consultants”) to indicate their interest in providing the Services. Interested Consultants should provide information demonstrating that they have the required qualifications and relevant experience to perform the Services. The shortlisting criteria are: • Legally registered consulting firm with at least 7+ years of experience in cybersecurity and digital risk advisory. • Demonstrated expertise in penetration testing, vulnerability assessment, and technical security evaluation for large, complex ICT environments. • Ability to deliver actionable, evidence-based recommendations to strengthen ICT resilience and mitigate sophisticated cyber threats. • Proven experience working with governmental, regulatory, or large enterprise environments. • Experience in comparable geographic or sectoral contexts is an advantage. • Capability to deliver strategic, actionable, and operationally relevant recommendations.
Key Experts will not be evaluated at the shortlisting stage. The attention of interested Consultants is drawn to Section III, paragraphs, 3.14, 3.16, and 3.17 of the World Bank’s “Procurement Regulations for IPF Borrowers” July 2016, revised November 2020 (“Procurement Regulations”), setting forth the World Bank’s policy on conflict of interest. Consultants may associate with other firms to enhance their qualifications but should indicate clearly whether the association is in the form of a joint venture and/or a sub-consultancy.
In the case of a joint venture, all the partners in the joint venture shall be jointly and severally liable for the entire contract, if selected. A Consultant will be selected in accordance with the Consultants’ Quality and Cost-based Selection method set out in the Procurement Regulations. Further information can be obtained at the address below during office hours 0900 to 1700 hours.
Expressions of interest must be delivered in a written form to the address below (in person, or by mail, or by e-mail) by 29 July 2026. African Union Commission, Head of Supply Chain Management Division Building C, 3rd Floor, P.O Box 3243, Roosevelt Street Addis Ababa, Ethiopia Tel: +251 (0) 11 551 7700 – Ext 4305 Fax: +251 (0) 11 551 0442; +251 11-551-0430 E-mail: Tender@africanunion.org TERMS OF REFERENCE CONSULTANCY SERVICES TO CONDUCT IT SECURITY ASSESSMENT FOR AFRICA UNION COMMISSION REF: ET-AUC-560866-CS-QCBS • I.
Background As the continental organization mandated to advance integration, peace, and sustainable development across Africa, the African Union Commission (AUC) increasingly relies on sophisticated Information and Communication Technology (ICT) systems to execute its mandate with efficiency, reliability, and accountability. The Commission’s ICT ecosystem, spanning headquarters and regional offices, integrates interconnected networks, mission-critical applications, and distributed services that are essential to achieving its operational and strategic priorities.
While this digital transformation has significantly enhanced connectivity, efficiency, and service delivery, it has also introduced a complex and evolving landscape of cybersecurity risks. In the current threat environment, cyber risks are not solely technical challenges; they carry strategic implications for institutional integrity, governance, and stakeholder trust. Safeguarding the AUC’s ICT assets is therefore a matter of organizational resilience, credibility, and confidence — core enablers for the Commission to effectively deliver its continental mandate.
The Management Information System Directorate (MISD), operating under the Cabinet of the Deputy Chairperson, is responsible for planning, deploying, and managing all ICT functions across the African Union. In its commitment to strengthening institutional cyber resilience, MISD recognizes the need for an independent, evidence-based Security Assessment of its ICT environment. This assessment will identify vulnerabilities, evaluate the effectiveness of existing safeguards, and provide actionable guidance to reinforce ICT security across all operational fields.
Accordingly, the African Union Commission invites proposals from highly qualified cybersecurity firms to conduct a comprehensive Security Assessment, incorporating both external and internal penetration testing. The assessment will simulate realistic cyber-threat scenarios, evaluate technical and operational resilience, and deliver prioritized recommendations for remediation. The outcomes will provide the Commission with a clear, actionable, and strategic understanding of its cybersecurity posture, supporting informed decision-making, strengthened operational continuity, and sustained institutional trust.
The main objectives of this Security Assessment will result in: • Identify critical vulnerabilities and attack paths across external-facing and internal ICT infrastructure, including misconfigurations, weak authentication mechanisms, and privilege escalation opportunities. • Strengthen organizational resilience to cyber threats by identifying exploitable vulnerabilities and simulating realistic attack scenarios, enabling the Commission to anticipate, withstand, respond to, and recover from potential incidents with minimal operational disruption. • Enhance the effectiveness of technical security controls by systematically evaluating networks, systems, applications, and configurations against recognized standards and international best practices. • Assess potential business and operational impacts of security breaches to provide leadership with clear insights into risk exposure and informed prioritization for remediation. • Provide prioritized, actionable recommendations for remediation, ensuring that targeted measures effectively reduce exposure, mitigate risks, and strengthen defenses across the Commission’s ICT environment. • Support continuous monitoring and improvement, delivering strategic insights that enable the MISD to maintain adaptive, resilient, and sustainable security measures over time. • Build confidence among stakeholders by producing high quality, evidence-based reporting suitable for leadership, technical teams, and external partners, fostering transparency and trust in the Commission’s security posture. • II.
A Precise Statement of Objective or Purpose The consultancy will develop a structured, actionable IT Security Remediation Plan based on the findings of a comprehensive penetration testing assessment of the African Union Commission’s ICT infrastructure. The plan will be multiannual, operational, and include prioritized initiatives with clearly assigned accountable owners, fully aligned with the Commission’s ICT governance framework and operational priorities. It will integrate targeted remediation measures, evidence-based recommendations, and a detailed implementation roadmap to strengthen the resilience and protection of critical ICT systems and services.
The firm will conduct a thorough penetration testing engagement, employing both external (black box) and internal (white box) methodologies. The assessment will systematically identify exploitable vulnerabilities, evaluate the effectiveness of existing technical controls, and simulate realistic threat scenarios across networks, servers, applications, and configurations. The outcomes will provide the Commission with actionable insights to guide the development and operationalization of a practical remediation plan.
The Security Assessment aims to deliver actionable insights that will: • Identify exploitable vulnerabilities across ICT systems including networks, servers, applications, and configurations revealing weaknesses that could be leveraged by malicious actors. • Simulate realistic cyberattack scenarios reflecting both external and insider threats, providing a clear understanding of the Commission’s security posture under operational conditions. • Evaluate the effectiveness of existing technical security controls, including detection, prevention, and response mechanisms. • Determine potential business and operational impacts of successful exploitation, enabling leadership to prioritize risk mitigation based on strategic and operational importance. • Provide prioritized, actionable recommendations for remediation, mitigation, and risk reduction, fully aligned with internationally recognized cybersecurity standards and best practices. • Support organizational resilience and continuous improvement, enabling MISD to enhance monitoring, governance, and long-term cybersecurity maturity. • III.
Scope of Work or Service Under the leadership of the MISD Director, the consultancy will conduct a comprehensive penetration testing assessment of the African Union Commission’s ICT infrastructure. The engagement is designed to rigorously evaluate technical controls, identify vulnerabilities, and simulate realistic cyberattac
What are the key dates?
Publication
July 14, 2026
Bid Submission Deadline
July 29, 2026
Evaluation & Award
Pending
Contract Signature
Pending
Procuring Entity
- Country
- Ethiopia
- Contact person
- Kaputo Chenga -Bwalya
Which documents are available?
Sign in to download the tender documents and be notified automatically of any change to this tender.
Similar tenders
Procurement of ICT Equipment — Government Communication Service
· IT & Telecom
Purchase of Laptop Computer Core i7 — Armauer Hansen Research Institute
· IT & Telecom
Procurement of Laptop Computers — Ethiopia Media Authority
· IT & Telecom
Procurement of ICT Equipment — Debremarkos University
· IT & Telecom
Procurement of Digital Engine Speed Control Unit 24V DC — Addis Ababa Road Authority
· IT & Telecom