Guangdong Agricultural Product Quality and Safety Improvement (Demonstration) Project Information Technology Service Package II (Cybersecurity Level Protection Assessment Service and Commercial Cryptography Application Security Evaluation Service)
A source-backed decision brief. The official notice and its addenda remain authoritative.
Project objective and employer selection criteria
1. Project objective
The currently available official record does not contain enough source text for a reliable project-objective summary.
Source / meaning
Official record metadata: USD 81,200سامانه رسمی مناقصات تدارکاتی بانک جهانی — official notice / tender document
Source / meaning
The total estimated amount for this project is RMB 0.56 million.سامانه رسمی مناقصات تدارکاتی بانک جهانی — official notice / tender document
Source / meaning
More than 10 years of experience in Cybersecurity Level Protection Assessment and Commercial Cryptography Application Security Assessment services.سامانه رسمی مناقصات تدارکاتی بانک جهانی — official notice / tender document
Source / meaning
More than 3 years of experience in Cybersecurity Level Protection Assessment and Commercial Cryptography Application Security Assessment services.سامانه رسمی مناقصات تدارکاتی بانک جهانی — official notice / tender document
Source / meaning
More than 3 years of practical experience in domestic cryptography upgrade and compliance assessment.سامانه رسمی مناقصات تدارکاتی بانک جهانی — official notice / tender document
View the official objective and scope excerpt
China Food Safety Improvement Project · Consultant Qualification Selection · شماره مرجع GD-FSS-GAMR-CS13
Extraction covers only the accessible source. Linked TORs and later addenda are not verified unless their text has been retrieved; a missing field never means no requirement.
Shortlisting / qualification criteria
Organisation history and structure
Not found among the extracted criteriaNo explicit requirement in this category appears among the criteria extracted from the currently available official text. Verify the complete notice, TOR and addenda.
Technical and managerial capability
1 explicit requirement(s)shortlisting criteria are: the overall competence and strength of the Consultant, quality control and project management capabilities, understanding of the assignment, relevant experience and past performance, proposed team composition, preliminary work plan, and a brief technical approach.
Prepare a matrix linking each required service to a reference assignment, firm role, delivered output and evidence, plus delivery organization and resources.
Preparation advice, not an additional employer requirement. Submit only the documents and formats required by the notice/TOR for this stage.Source excerpt for this employer criterion
shortlisting criteria are: the overall competence and strength of the Consultant, quality control and project management capabilities, understanding of the assignment, relevant experience and past performance, proposed team composition, preliminary work plan, and a brief technical approach.Source location: سامانه رسمی مناقصات تدارکاتی بانک جهانی — shortlisting / qualification criteria
Similar experience
Not found among the extracted criteriaNo explicit requirement in this category appears among the criteria extracted from the currently available official text. Verify the complete notice, TOR and addenda.
Key personnel
2 explicit requirement(s)shortlisting criteria are: the overall competence and strength of the Consultant, quality control and project management capabilities, understanding of the assignment, relevant experience and past performance, proposed team composition, preliminary work plan, and a brief technical approach. Key Experts will be evaluated at the shortlisting stage. (VII) Contents of this Consultation a.Expression of interest in undertaking the supervision services for this project; b.Agency profile and core advantages;
Map each stated role to its CV, qualifications, references and availability; verify the required format and submission stage.
Preparation advice, not an additional employer requirement. Submit only the documents and formats required by the notice/TOR for this stage.Source excerpt for this employer criterion
shortlisting criteria are: the overall competence and strength of the Consultant, quality control and project management capabilities, understanding of the assignment, relevant experience and past performance, proposed team composition, preliminary work plan, and a brief technical approach. Key Experts will be evaluated at the shortlisting stage. (VII) Contents of this Consultation a.Expression of interest in undertaking the supervision services for this project; b.Agency profile and core advantages;Source location: سامانه رسمی مناقصات تدارکاتی بانک جهانی — shortlisting / qualification criteria
f.Proposed core team (including resume summaries of the Project Manager and key experts). (VIII) Submission Materials a."Expression of Interest Letter" (or "Feedback Letter") submitted by the supervision service agency; b.Agency profile; c.Summary of project performance records (specifying the project name, client, service content, and service period);
Map each stated role to its CV, qualifications, references and availability; verify the required format and submission stage.
Preparation advice, not an additional employer requirement. Submit only the documents and formats required by the notice/TOR for this stage.Source excerpt for this employer criterion
f.Proposed core team (including resume summaries of the Project Manager and key experts). (VIII) Submission Materials a."Expression of Interest Letter" (or "Feedback Letter") submitted by the supervision service agency; b.Agency profile; c.Summary of project performance records (specifying the project name, client, service content, and service period);Source location: سامانه رسمی مناقصات تدارکاتی بانک جهانی — shortlisting / qualification criteria
Eligibility and legal requirements
1 explicit requirement(s)b. neither a Consultant (including personnel and sub-consultants), nor an affiliate (that directly or indirectly controls, is controlled by, or is under common control with that Consultant), shall be hired for any assignment that, by its nature, creates a conflict of interest with another assignment of the Consultant;
Prepare a declaration and records of ownership, affiliations and relevant prior assignments for conflict review.
Preparation advice, not an additional employer requirement. Submit only the documents and formats required by the notice/TOR for this stage.Source excerpt for this employer criterion
b. neither a Consultant (including personnel and sub-consultants), nor an affiliate (that directly or indirectly controls, is controlled by, or is under common control with that Consultant), shall be hired for any assignment that, by its nature, creates a conflict of interest with another assignment of the Consultant;Source location: سامانه رسمی مناقصات تدارکاتی بانک جهانی — shortlisting / qualification criteria
Company financial capacity
Not found among the extracted criteriaNo explicit requirement in this category appears among the criteria extracted from the currently available official text. Verify the complete notice, TOR and addenda.
Other employer-specific criteria
1 explicit requirement(s)a. a firm that has been engaged by the Borrower to provide Goods, Works, or Non-Consulting Services for a project (or an affiliate that directly or indirectly controls, is controlled by, or is under common control with that firm), shall be disqualified from providing Consulting Services resulting from, or directly related to, those Goods, Works, or Non-Consulting Services.
Map this exact clause to verifiable evidence and confirm format, issuer and validity with the employer documents; an unspecified document is not an employer requirement.
Preparation advice, not an additional employer requirement. Submit only the documents and formats required by the notice/TOR for this stage.Source excerpt for this employer criterion
a. a firm that has been engaged by the Borrower to provide Goods, Works, or Non-Consulting Services for a project (or an affiliate that directly or indirectly controls, is controlled by, or is under common control with that firm), shall be disqualified from providing Consulting Services resulting from, or directly related to, those Goods, Works, or Non-Consulting Services.Source location: سامانه رسمی مناقصات تدارکاتی بانک جهانی — shortlisting / qualification criteria
Complete retrieved official text
REQUEST FOR EXPRESSIONS OF INTEREST INFORMATION TECHNOLOGY CYBERSECURITY LEVEL PROTECTION ASSESSMENT SERVICE AND COMMERCIAL CRYPTOGRAPHY APPLICATION SECURITY EVALUATION SERVICE for China Food Safety Improvement Project Guangdong Agricultural Product Quality and Safety Improvement (Demonstration) Project Country: People's Republic of China Name of Project: China Food Safety Improvement Project Loan No.: IBRD-92130 Assignment Title: Guangdong Agricultural Product Quality and Safety Improvement (Demonstration) Project Information Technology Third-Party Service Package II (Cybersecurity Level Protection Assessment Service and Commercial Cryptography Application Security Evaluation Service) Reference No.: GD-FSS-GAMR-CS13 The Guangdong Administration for Market Regulation has received financing from the World Bank toward the cost of the China Food Safety Improvement Project Guangdong Agricultural Product Quality and Safety Improvement (Demonstration) Project, and intends to apply part of the proceeds for consulting services. The total estimated amount for this project is RMB 0.56 million. (I) Scope of Service The service scope of this project covers the Cybersecurity Level Protection Assessment and Commercial Cryptography Application Security Assessment services required for four informatization projects, specifically including: • The "Scan-to-Trace" Full-Chain Traceability Platform Project for Food in Key Fields (Categories); • The "Yue-Shi-An Internet Plus Open Kitchens" System Construction Project; • The Upgrade, Renovation, and Operation Project of the Emergency Real-Time Dispatch and Command System; • The Capacity Building Project for Food-Related Personnel in Market Regulation. (II) Service Contents 1. Cybersecurity Level Protection Assessment Services Based on the assessment results of security technology and security management controls, as well as the overall system assessment, the service agency shall conduct a comprehensive assessment of the information system in accordance with the corresponding level standards and provide relevant security review opinions. This specifically includes two aspects: First, security control assessment, which primarily evaluates the implementation and configuration of basic security controls required by the cybersecurity level protection standards within the information system. Second, overall system assessment, which primarily analyzes the overall security of the information system. The security control assessment serves as the foundation for the overall security assessment of the information system. 2. Commercial Cryptography Application Security Assessment Services The service agency shall provide security assessment services for systems upgraded with domestic cryptography. For the upgraded national cryptographic systems, the agency shall formulate an assessment plan, conduct the assessment, propose rectification opinions, and track the rectification progress in accordance with national specifications, thereby providing a basis for project acceptance. Through this assessment service, the agency will comprehensively understand the current status of cryptography application in the relevant information systems and evaluate the gap between the current status and the corresponding levels stipulated in the Information Security Technology—Basic Requirements for Cryptographic Application of Information Systems (GB/T 39786-2021). This aims to achieve the goals of promoting construction, rectification, and application through assessment. On-site assessments and technical verifications will be conducted covering physical and environmental security, network and communication security, equipment and computing security, application and data security, key management, and security management. The agency will identify weak links and potential risk hazards in cryptographic applications, propose targeted rectification recommendations, and ensure the compliance, correctness, and effectiveness of cryptographic applications. Furthermore, cryptographic security protection measures will be precisely implemented to guarantee the authenticity, confidentiality, integrity, and non-repudiation of the information systems. (III) Service Period The service period for this project shall commence from the date of contract signing and continue until the project closing date (March 31, 2029). The specific service timeline will be implemented in phases based on the system launch schedule of the four informatization projects. (IV) Deliverables The deliverables required for this project are as follows: No. Report Submission Date/Phase 1 Mobilization Report Within 10 working days after contract signing and system launch (subject to the actual system launch date). 2 Information System Rectification List Within 10 working days after the completion of the gap assessment. 3 Cybersecurity Level Protection Assessment Report For Level 3 systems: Within 15 working days after the acceptance assessment is conducted upon the user's completion of rectification to meet the acceptance requirements. For the annual re-assessment report: The annual re-assessment must be initiated 3 months before the expiration of the previous year's assessment report, and the annual assessment report must be issued before the expiration of the previous year's report. For Level 2 systems: Within 15 working days after the acceptance assessment is conducted upon the user's completion of rectification to meet the acceptance requirements. 4 Filing Materials and Filing Receipt Issued within 10 working days after the assessment report is stamped by both parties and submitted online to the cyber police department. 5 Commercial Cryptography Application Rectification List Within 10 working days after the completion of the gap assessment. 6 Commercial Cryptography Application Security Assessment Report For Level 3 systems: Within 15 working days after the acceptance assessment is conducted upon the user's completion of rectification to meet the cryptographic assessment acceptance requirements. For the annual re-assessment report: The annual re-assessment must be initiated 3 months before the expiration of the previous year's assessment report, and the annual assessment report must be issued before the expiration of the previous year's report. For Level 2 systems: Within 15 working days after the acceptance assessment is conducted upon the user's completion of rectification to meet the cryptographic assessment acceptance requirements. 7 Filing Materials and Filing Receipt Issued within 10 working days after the assessment report is stamped by both parties and submitted to the Cryptography Administration. Upon receiving the deliverable reports submitted by the assessment service agency, the Project Management Office (PMO) shall review them. For deliverable documents that are required to be submitted to the World Bank for review according to regulations, the assessment service agency shall assist the PMO in completing the submission. The phased deliverables shall be officially considered closed only after obtaining the World Bank's "no objection." All deliverable reports must fully align with the service content specified in this Terms of Reference (TOR). They must be standardized in format, comprehensive in content, and authentic and accurate in data. (V) Consultant Qualification Requirements The service agency must possess the Cybersecurity Service (Level Protection Assessment) Certification Certificate issued by the Third Research Institute of the Ministry of Public Security, as well as the Commercial Cryptography Testing Agency (Commercial Cryptography Application Security Assessment) Qualification Certificate issued by the State Cryptography Administration. Within the past three years, the agency must have independently undertaken no fewer than five service projects for Cybersecurity Level Protection Assessment and Commercial Cryptography Application Security Assessment. The relevant performance records must cover related types such as government informatization, software platform construction, system integration, and network security. These records must sufficiently demonstrate the agency's capability in compliance assessment and comprehensive security services for informatization projects. Regarding the assessment tools required for the service agency, different testing tools shall be equipped based on the testing content of this project. Examples include comprehensive management software for level protection assessment, network security inspection and early warning management software, quality monitoring management software for level protection assessment, level protection assessment management and risk assessment software, and commercial cryptography application security assessment management systems. The service agency shall provide an equipment plan for the testing tools to be used in this project within the technical proposal. (Note: For purchased assessment tools, procurement contracts and invoices must be provided; for self-developed tools, software copyrights or relevant patent certificates must be provided). (VI) Expert Qualifications The consulting service agency shall primarily deploy key personnel and teams, including the Project Manager, Technical Director, Level Protection Assessment Task Force, and Cryptographic Assessment Task Force. The qualification requirements and functional responsibilities for each key position are as follows: No. Expert Position Qty. Responsibilities Qualifications 1 Project Manager 1 Responsible for overall coordination, resource allocation, and cross-departmental communication throughout the entire project lifecycle. Control the quality of all deliverables, including the mobilization report and assessment reports. Organize project acceptance and assist in completing the filing (record-keeping) process. 1. Bachelor's degree or above; 2. Possess competency certificates in information security, data security, network, and informatization project management; 3. More than 10 years of experience in Cybersecurity Level Protection Assessment and Commercial Cryptography Application Security Assessment services. 2 Technical Director 1 Take the lead in drafting the implementation plans for level protection and cryptographic assessments. Provide on-site technical supervision, analyze complex hidden risks, provide technical solutions for rectification and reinforcement, and review the objectivity and accuracy of the assessment reports. 1. Bachelor's degree or above; 2. Possess competency certificates in information security, data security, network, and informatization project management; 3. More than 10 years of experience in Cybersecurity Level Protection Assessment and Commercial Cryptography Application Security Assessment services. 3 Level Protection Assessment Task Force 2 Responsible for on-site investigation, asset inventory, penetration testing, and security control assessment. Draft the "Information System Rectification List" and the "Cybersecurity Level Protection Assessment Report," and assist in completing the filing with the cyber police department. 1. Bachelor's degree or above; 2. Possess competency certificates in information security, data security, network, and informatization project management; 3. More than 3 years of experience in Cybersecurity Level Protection Assessment and Commercial Cryptography Application Security Assessment services. 4 Cryptographic Assessment Task Force 2 Responsible for compliance verification and risk identification of systems upgraded with national cryptography. Verify the compliance, correctness, and effectiveness of domestic cryptographic algorithm (SM2/SM3/SM4) invocations. Draft the "Commercial Cryptography Application Security Assessment Report" and rectification lists, and assist in completing the filing with the cryptography administration. 1. Bachelor's degree or above; 2. Familiar with the GB/T 39786-2021 standard; practitioner in commercial cryptography application security assessment; 3. More than 3 years of practical experience in domestic cryptography upgrade and compliance assessment. The detailed Terms of Reference (TOR) for the assignment are attached to this request for expressions of interest. The Guangdong Administration for Market Regulation now invites eligible consulting firms (“Consultants”) to indicate their interest in providing the Services. Interested Consultants should provide information demonstrating that they have the required qualifications and relevant experience to perform the Services. The shortlisting criteria are: the overall competence and strength of the Consultant, quality control and project management capabilities, understanding of the assignment, relevant experience and past performance, proposed team composition, preliminary work plan, and a brief technical approach. Key Experts will be evaluated at the shortlisting stage. (VII) Contents of this Consultation a.Expression of interest in undertaking the supervision services for this project; b.Agency profile and core advantages; c.List of project performance records; d.Key points of the preliminary work plan and work schedule; e.Preliminary staffing plan; f.Proposed core team (including resume summaries of the Project Manager and key experts). (VIII) Submission Materials a."Expression of Interest Letter" (or "Feedback Letter") submitted by the supervision service agency; b.Agency profile; c.Summary of project performance records (specifying the project name, client, service content, and service period); d.Simplified proposal (briefly outlining key points; a detailed proposal is not required); e.Preliminary work schedule; f.Key team experts (personnel profiles must be provided); g.Any other materials deemed necessary by the supervision service agency. Note: All the above materials must be stamped with the official seal of the consulting agency. Consultants shall not be hired for any assignment that would be in conflict with their prior or current obligations to other clients, or that may place them in a position of being unable to carry out the assignment in the best interests of the Borrower. Without limitation on the generality of the foregoing, Consultants shall not be hired under the circumstances set forth below: a. a firm that has been engaged by the Borrower to provide Goods, Works, or Non-Consulting Services for a project (or an affiliate that directly or indirectly controls, is controlled by, or is under common control with that firm), shall be disqualified from providing Consulting Services resulting from, or directly related to, those Goods, Works, or Non-Consulting Services. This provision does not apply to the various firms (Consultants, contractors, or suppliers), which together are performing the contractor’s obligations under a turnkey or design and build contract; a firm that has been engaged by the Borrower to provide Consulting Services for the preparation or implementation of a project (or an affiliate that directly or indirectly controls, is controlled by, or is under common control with that Consulting firm), shall be disqualified from subsequently providing Goods, Works, or Non-Consulting Services resulting from, or directly related to those Consulting Services. This provision does not apply to the various firms (Consultants, contractors, or suppliers), which together are performing the contractor’s obligations under a turnkey or design and build contract; b. neither a Consultant (including personnel and sub-consultants), nor an affiliate (that directly or indirectly controls, is controlled by, or is under common control with that Consultant), shall be hired for any assignment that, by its nature, creates a conflict of interest with another assignment of the Consultant; c. Consultants (including their experts and other personnel, and sub-consultants), that have a close business or family relationship with a professional staff of the Borrower, or of the project implementing agency, or of a recipient of a part of the Bank’s financing, or any other party representing or acting on behalf of the Borrower, that is directly or indirectly involved in any part of: i. the preparation of the ToR for the assignment; ii. the selection process for the contract; or iii. the supervision of the contract; may not be awarded a contract, unless the conflict stemming from this relationship has been resolved in a manner acceptable to the Bank throughout the selection process and the execution of the contract. Consultants may associate with other firms to enhance their qualifications, but should indicate clearly whether the association is in the form of a joint venture and/or a sub-consultancy. In the case of a joint venture, all the partners in the joint venture shall be jointly and severally liable for the entire contract, if selected. A Consultant will be selected in accordance with the CQS method set out in the Procurement Regulations. Further information can be obtained at the address below during office hours. Office hours are from 09:00 to 17:00 on working days from September 12 to September 29, 2026 Expressions of interest must be delivered in a written form to the address below (in person, or by mail, or by fax, or by e-mail) by 09:00 on September 30, 2026. Tender Agency: China International Tendering Co., Ltd. Attn: Zhang Zhi, Guo Hujun Title: Project Manager Address: Room 2003B, South Tower, Jinbin Tengyue Building, Huaxia Road No. 49-1, Tianhe District, Guangzhou, Guangdong Province, China Postal Code:51000 Tel.: 010-81168424; 010-81168460 E-mail: zhangzhi5@cgci.gt.cn; guohujun@gt.cn Employer: Guangdong Administration for Market Regulation Attn: Chen Lin Title: Special Cadre, World Bank Loan Project Office Address: No. 363 West Huangpu Avenue, Tianhe District, Guangzhou, Guangdong Province, China Tel.: 020-38835493 E-mail: gdsjj_xietiaoyingji@gd.gov.cn Annex: Detailed Term of Reference (TOR) TERM OF REFERENCE To ensure the implementation of the World Bank China Food Safety Improvement Project Guangdong Agricultural Product Quality and Safety Improvement (Demonstration) Project Information Technology Third-Party Service Package II (Cybersecurity Level Protection Assessment Service and Commercial Cryptography Application Security Evaluation Service) of the Guangdong Administration for Market Regulationand to guarantee the achievement of the project's objectives, the Guangdong Administration for Market Regulation intends to select a service agency through procurement to be responsible for the implementation of this project. I. Background and Description The World Bank Loan China Food Safety Demonstration Project officially entered into force on March 21, 2024, with an implementation period until March 31, 2029. It aims to comprehensively enhance the modern governance capacity for food safety at both national and local levels. As a key implementer of this project in Guangdong Province, the Guangdong Administration for Market Regulation plans to apply for a World Bank loan of 10 million US dollars and will precisely support the achievement of the project goals through the construction of six core sub-projects: i. Develop a full-chain traceability platform for "coding, tracing, and recalling" food in key areas, enabling whole-process traceability and risk early warning with 15 functional modules and 359 functional points; ii. Build the "Internet + Clear Kitchen and Bright Stove" system under the Guangdong Food Safety initiative, covering intelligent video supervision of scenarios such as elderly care and campus canteens; iii. Upgrade and transform the emergency real-time dispatching and command system, and improve the accident emergency response mechanism; iv. Carry out a capacity improvement project for food-related personnel in the market supervision field, including the development of a learning and assessment system, the production of 75 course videos, and the organization of skill competitions; v. Establish a high-quality food standard system and conduct promotion activities, developing no less than 30 standards and carrying out quality monitoring within two years; vi. Provide professional consulting services throughout the entire project implementation process. To ensure the high-quality implementation of the above-mentioned construction content, we plan to refer to advanced practices from other World Bank projects to further optimize procurement management and improve service coordination efficiency; in the next phase of actual procurement operations, while keeping the total project budget unchanged, we intend to integrate the network security level protection assessment services and commercial cryptography application security assessment services for these 4 projects—the "Coding, Tracing, and Recalling" Full-Chain Traceability Platform Project for Food in Key Areas (or Key Varieties), the Guangdong Food Safety "Internet + Clear Kitchen and Bright Stove" System Construction Project, the Emergency Real-Time Dispatching and Command System Upgrade, Transformation, and Operation Project, and the Capacity Improvement Project for Food-Related Personnel in the Market Supervision Field—into a single package for unified procurement and management, so as to ensure the smooth achievement of the project's construction goals. II. Objectives The core objective of this project is to comprehensively enhance the modern governance capacity for food safety. Through the in-depth integration and linkage of the "Code Tracing" full-chain traceability platform, the "Internet + Smart Kitchen & Bright Stove" intelligent supervision system, and the emergency real-time dispatch and command system, a full-chain management mechanism covering risk identification, early warning response, and closed-loop disposal will be established, providing a data foundation and institutional guarantee for scientifically calculating result indicators such as the "proportion of early warnings for which mitigation measures have been initiated." Additionally, the food-related personnel capacity improvement learning and assessment system will enable systematic training for regulatory personnel and quantify the participation proportion of female regulatory personnel. The core purpose is to conduct a comprehensive and objective security assessment of the above-mentioned information systems in accordance with relevant national standards and norms, accurately identify and locate risks and weaknesses in the systems' network security and cryptographic applications, and propose targeted rectification suggestions accordingly. Through the approach of "promoting construction through assessment, promoting reform through assessment, and promoting application through assessment," it will ultimately ensure that all information systems meet the requirements of compliance, correctness, and effectiveness in terms of network security protection and cryptographic applications. This will provide a solid guarantee for the smooth acceptance and safe operation of the project, ensure that the collection, accounting, and reporting of all indicator data comply with World Bank norms, and help promote the efficient implementation of the World Bank project. III. Service Overview The total estimated amount for this project is RMB 0.56 million. (I) Scope of Services The service scope of this project covers the Cybersecurity Level Protection Assessment and Commercial Cryptography Application Security Assessment services required for four informatization projects, specifically including: • The "Scan-to-Trace" Full-Chain Traceability Platform Project for Food in Key Fields (Categories); • The "Yue-Shi-An Internet Plus Open Kitchens" System Construction Project; • The Upgrade, Renovation, and Operation Project of the Emergency Real-Time Dispatch and Command System; • The Capacity Building Project for Food-Related Personnel in Market Regulation. (II) Service Content a. Cybersecurity Level Protection Assessment Services Based on the assessment results of security technology and security management controls, as well as the overall system assessment, the service agency shall conduct a comprehensive assessment of the information system in accordance with the corresponding level standards and provide relevant security review opinions. This specifically includes two aspects: First, security control assessment, which primarily evaluates the implementation and configuration of basic security controls required by the cybersecurity level protection standards within the information system. Second, overall system assessment, which primarily analyzes the overall security of the information system. The security control assessment serves as the foundation for the overall security assessment of the information system. b. Commercial Cryptography Application Security Assessment Services The service agency shall provide security assessment services for systems upgraded with domestic cryptography. For the upgraded national cryptographic systems, the agency shall formulate an assessment plan, conduct the assessment, propose rectification opinions, and track the rectification progress in accordance with national specifications, thereby providing a basis for project acceptance. Through this assessment service, the agency will comprehensively understand the current status of cryptography application in the relevant information systems and evaluate the gap between the current status and the corresponding levels stipulated in the Information Security Technology—Basic Requirements for Cryptographic Application of Information Systems (GB/T 39786-2021). This aims to achieve the goals of promoting construction, rectification, and application through assessment. On-site assessments and technical verifications will be conducted covering physical and environmental security, network and communication security, equipment and computing security, application and data security, key management, and security management. The agency will identify weak links and potential risk hazards in cryptographic applications, propose targeted rectification recommendations, and ensure the compliance, correctness, and effectiveness of cryptographic applications. Furthermore, cryptographic security protection measures will be precisely implemented to guarantee the authenticity, confidentiality, integrity, and non-repudiation of the information systems. (III) Service Period The service period for this project shall commence from the date of contract signing and continue until the project closing date (March 31, 2029). The specific service timeline will be implemented in phases based on the system launch schedule of the four informatization projects. IV Deliverables, Result Review and Acceptance a.Deliverables The deliverables required for this project are as follows: No. Report Submission Date/Phase 1 Mobilization Report Within 10 working days after contract signing and system launch (subject to the actual system launch date). 2 Information System Rectification List Within 10 working days after the completion of the gap assessment. 3 Cybersecurity Level Protection Assessment Report For Level 3 systems: Within 15 working days after the acceptance assessment is conducted upon the user's completion of rectification to meet the acceptance requirements. For the annual re-assessment report: The annual re-assessment must be initiated 3 months before the expiration of the previous year's assessment report, and the annual assessment report must be issued before the expiration of the previous year's report. For Level 2 systems: Within 15 working days after the acceptance assessment is conducted upon the user's completion of rectification to meet the acceptance requirements. 4 Filing Materials and Filing Receipt Issued within 10 working days after the assessment report is stamped by both parties and submitted online to the cyber police department. 5 Commercial Cryptography Application Rectification List Within 10 working days after the completion of the gap assessment. 6 Commercial Cryptography Application Security Assessment Report For Level 3 systems: Within 15 working days after the acceptance assessment is conducted upon the user's completion of rectification to meet the cryptographic assessment acceptance requirements. For the annual re-assessment report: The annual re-assessment must be initiated 3 months before the expiration of the previous year's assessment report, and the annual assessment report must be issued before the expiration of the previous year's report. For Level 2 systems: Within 15 working days after the acceptance assessment is conducted upon the user's completion of rectification to meet the cryptographic assessment acceptance requirements. 7 Filing Materials and Filing Receipt Issued within 10 working days after the assessment report is stamped by both parties and submitted to the Cryptography Administration. b. Result Review and Acceptance After the Project Office reviews and approves the outcome report submitted by the assessment service agency, for the outcome documents that need to be submitted to the World Bank for review in accordance with regulations, the assessment service agency shall cooperate with the Project Office to complete the submission. The phased outcome shall be officially considered completed only after obtaining the World Bank's no-objection opinion. All outcome reports must fully align with the service content specified in this Terms of Reference, with standardized format, complete content, and true and accurate data. V Agency and Personnel Qualification Requirements a. Agency Qualification Requirements The service agency must possess the Cybersecurity Service (Level Protection Assessment) Certification Certificate issued by the Third Research Institute of the Ministry of Public Security, as well as the Commercial Cryptography Testing Agency (Commercial Cryptography Application Security Assessment) Qualification Certificate issued by the State Cryptography Administration. Within the past three years, the agency must have independently undertaken no fewer than five service projects for Cybersecurity Level Protection Assessment and Commercial Cryptography Application Security Assessment. The relevant performance records must cover related types such as government informatization, software platform construction, system integration, and network security. These records must sufficiently demonstrate the agency's capability in compliance assessment and comprehensive security services for informatization projects. Regarding the assessment tools required for the service agency, different testing tools shall be equipped based on the testing content of this project. Examples include comprehensive management software for level protection assessment, network security inspection and early warning management software, quality monitoring management software for level protection assessment, level protection assessment management and risk assessment software, and commercial cryptography application security assessment management systems. The service agency shall provide an equipment plan for the testing tools to be used in this project within the technical proposal. (Note: For purchased assessment tools, procurement contracts and invoices must be provided; for self-developed tools, software copyrights or relevant patent certificates must be provided). b. Personnel Qualification Requirements To ensure the quality of the network security level protection assessment service and commercial cryptography application security assessment service for this project, an exclusive full-time service team must be established. The specific requirements are as follows: No. Expert Position Qty. Responsibilities Qualifications 1 Project Manager 1 Responsible for overall coordination, resource allocation, and cross-departmental communication throughout the entire project lifecycle. Control the quality of all deliverables, including the mobilization report and assessment reports. Organize project acceptance and assist in completing the filing (record-keeping) process. 1. Bachelor's degree or above; 2. Possess competency certificates in information security, data security, network, and informatization project management; 3. More than 10 years of experience in Cybersecurity Level Protection Assessment and Commercial Cryptography Application Security Assessment services. 2 Technical Director 1 Take the lead in drafting the implementation plans for level protection and cryptographic assessments. Provide on-site technical supervision, analyze complex hidden risks, provide technical solutions for rectification and reinforcement, and review the objectivity and accuracy of the assessment reports. 1. Bachelor's degree or above; 2. Possess competency certificates in information security, data security, network, and informatization project management; 3. More than 10 years of experience in Cybersecurity Level Protection Assessment and Commercial Cryptography Application Security Assessment services. 3 Level Protection Assessment Task Force 2 Responsible for on-site investigation, asset inventory, penetration testing, and security control assessment. Draft the "Information System Rectification List" and the "Cybersecurity Level Protection Assessment Report," and assist in completing the filing with the cyber police department. 1. Bachelor's degree or above; 2. Possess competency certificates in information security, data security, network, and informatization project management; 3. More than 3 years of experience in Cybersecurity Level Protection Assessment and Commercial Cryptography Application Security Assessment services. 4 Cryptographic Assessment Task Force 2 Responsible for compliance verification and risk identification of systems upgraded with national cryptography. Verify the compliance, correctness, and effectiveness of domestic cryptographic algorithm (SM2/SM3/SM4) invocations. Draft the "Commercial Cryptography Application Security Assessment Report" and rectification lists, and assist in completing the filing with the cryptography administration. 1. Bachelor's degree or above; 2. Familiar with the GB/T 39786-2021 standard; practitioner in commercial cryptography application security assessment; 3. More than 3 years of practical experience in domestic cryptography upgrade and compliance assessment. VI. Facilities and Personnel Provided by the Client To ensure the smooth implementation of the service, the Client will provide the following necessary assistance and services: a. Relevant project documents, reports, annual work plans and other materials. b. Designate or entrust staff to coordinate with the service provider and carry out related work.
Document, security and collaboration conditions
Consortium and local-partner condition
The official text contains consortium or joint-venture conditions, but the currently available wording does not conclusively establish whether that structure is permitted or mandatory.
View 2 exact source clause(s)
b. neither a Consultant (including personnel and sub-consultants), nor an affiliate (that directly or indirectly controls, is controlled by, or is under common control with that Consultant), shall be hired for any assignment that, by its nature, creates a conflict of interest with another assignment of the Consultant;Locator: سامانه رسمی مناقصات تدارکاتی بانک جهانی — shortlisting / qualification criteria
Consultants (including their experts and other personnel, and sub-consultants), that have a close business or family relationship with a professional staff of the Borrower, or of the project implementing agency, or of a recipient of a part of the Bank’s financing, or any other party representing or acting on behalf of the Borrower, that is directly or indirectly involved in any part of: i. the preparation of the ToR for the assignment; ii. the selection process for the contract; or iii. the supervision of the contract; may not be awarded a contract, unless the conflict stemming from this relationship has been resolved in a manner acceptable to the Bank throughout the selection process and the execution of the contractLocator: سامانه رسمی مناقصات تدارکاتی بانک جهانی — shortlisting / qualification criteria
Unstated means “not found in the official text currently available to FANAB”, not “not required”. Always verify the complete notice, TOR and addenda.
