Guangdong Agricultural Product Quality and Safety Improvement (Demonstration) Project Information Technology Service Package III (Specialized Security Assessment Service and Acceptance Assessment Service)
A source-backed decision brief. The official notice and its addenda remain authoritative.
Project objective and employer selection criteria
1. Project objective
Scope of services
Total investment for this project amounts to RMB 420,000. 3.1 Scope of Service Recipients The scope of services of this project covers special security evaluation services and acceptance evaluation services for four information-based sub-projects, specifically as follows: 1.Full-chain food traceability platform project with "ShangMa Su" for key food sectors (categories); 2.Guangdong Food Safety "Internet-based Visualization Kitchen" system construction project; 3.Upgrading, renovation and operation project of the real-time emergency dispatching command system; 4.Capacity improvement project for food-related personnel in the market supervision field. 3.2 Service Content 3.2.1 Special Security Evaluation Service Before the system launch on the Guangdong E-Government Cloud or domestic cloud, the service provider shall conduct a pre-launch security evaluation of the system. The security evaluation institution shall conduct non-destructive penetration testing on the system by simulating hacker attack methods. The objective is to attempt system intrusion and obtain system control privileges, and deliver a report to the Client documenting the intrusion process and details. The evaluation shall focus on networks, hosts, applications, data and the overall system, to assess whether the system has adequate capabilities of information security protection, meets the safety management and control requirements of the industry and competent authorities, can continuously provide secure, stable and efficient business support, and can safeguard sensitive information and public privacy. 3.2.2 Acceptance Evaluation Services Before the final project acceptance, the service provider shall conduct pre-acceptance evaluation and compliance inspection for the informatization service project to strictly control project quality, so as to ensure that all indicators fully comply with the contract, requirement specification and construction specifications. The scope mainly includes functional testing, performance efficiency testing, information security testing, compatibility testing, reliability testing, usability testing, maintainability testing, portability testing, and documentation review, among others. 3.3 Service Period The service period shall commence on the date of contract signing and end on the project closure date (March 31, 2029). The specific service schedule shall be implemented in phases in accordance with the system launch and acceptance progress of the four informatization sub-projects. 4. Deliverables, Review and Acceptance 4.1 Deliverables The deliverables required under this project are set out below: No. Report Name Submission Timing / Stage 1 Project Start Date Start date for acceptance testing: subject to the project’s preliminary acceptance date; Start date for security testing: subject to the system launch date. 2 Acceptance Evaluation Plan To be submitted within 10 working days after receipt of project documents. 3 Acceptance Test Issue Report To be submitted within 5 working days upon completion of the first round of testing. 4 Acceptance Evaluation Report To be submitted within 5 working days upon completion of regression testing. 5 Security Evaluation Plan To be submitted within 10 working days after receipt of project documents. 6 Security Evaluation Issue Report To be submitted within 5 working days upon completion of the first round of testing. 7 Security Evaluation Report To be submitted within 5 working days upon completion of regression testing. 4.2 Deliverable Review and Acceptance After the Project Office reviews and approves submitted deliverable reports, the service provider shall cooperate with the Project Office to submit documents required for World Bank review, and the stage deliverables shall only be formally finalized upon receiving a no-objection opinion from the World Bank. All deliverables shall fully comply with the service requirements specified in this TOR, with standardized format, complete content and authentic, accurate data. 5.Institutional and Personnel Qualification Requirements 5.1 Institutional Qualifications 5.1.1 Qualification Requirements for the Service Provider The service provider undertaking both special security evaluation and acceptance evaluation services shall hold valid qualifications: either the Certificates of Accreditation for Testing Laboratories (including CNAS Laboratory Accreditation Certificates) issued by the China National Accreditation Service for Conformity Assessment (CNAS), or the Certificate of Metrology Accreditation (CMA) issued by market supervision authorities at or above the provincial level. The service provider shall have independently completed no fewer than 5 projects of special security evaluation and acceptance evaluation services within the past three years. Such track records shall cover government informatization, software platform development, system integration, cybersecurity and other relevant categories, which can fully demonstrate the provider’s comprehensive service capacity to conduct pre-launch security evaluation and final quality control for complex informatization projects. 5.2 Personnel Qualifications To ensure the quality of the special security evaluation service and acceptance evaluation service under this project, a dedicated service team shall be assigned. The job responsibilities, academic qualifications, working experience and professional competency requirements for each role are set out as follows: No. Team Role Number of Staff Job Responsibilities Qualification Requirements 1 Project Manager 1 Overall project life-cycle coordination, resource allocation, cross-department communication; develop detailed evaluation implementation plan and schedule; fully control the quality of all deliverables including project start report, test plan and final evaluation report; conduct daily communication and reporting with the Client and supervision unit; organize project acceptance and assist in completing relevant filing work. 1. Bachelor's degree or above; 2. Possess competency certificate for informatization project management. 3.Over 10 years of working experience in special security evaluation and acceptance evaluation services. 2 Project Technical Leader 1 Take the lead in developing the Acceptance Test Plan and technical plan for special security evaluation; provide technical oversight for on-site evaluation work; conduct in-depth analysis and risk grading for complex vulnerabilities identified during penetration testing and functional testing; propose practical technical solutions for rectification and hardening against system defects; review the objectivity, accuracy and logical rigor of test reports. 1. Bachelor's degree or above; 2. Possess competency certificates in software, cybersecurity and related fields. 3.Over 10 years of working experience in cybersecurity and software acceptance. 3 Special Security Evaluation Team 2 Responsible for pre-launch special security evaluation of the system; conduct non-destructive penetration testing and vulnerability scanning on networks, hosts, applications, data and the overall system by simulating hacker attacks with professional tools; assess whether the system meets the safety management and control requirements of the industry and competent authorities; prepare the Security Test Report and Rectification Recommendations, and guide and cooperate with the rectification party to complete security hardening. 1. Bachelor’s degree or above; 2. Possess national competency certificates in registered penetration testing, information security, network and related fields; 3. Familiar with mainstream penetration testing tools and have practical experience in security evaluation under the Guangdong E-Government Cloud or domestic cloud environment. 4 Acceptance Evaluation Team 2 Responsible for pre-acceptance evaluation and compliance inspection of the project; conduct functional testing, performance efficiency testing, information security testing, compatibility testing, reliability testing, usability testing, maintainability testing, portability testing, and documentation review in strict accordance with the requirement specification; record issues identified during testing process and prepare the Issue Report; summarize test results and prepare standardized Acceptance Test Report to ensure all indicators comply with construction standards. • Bachelor’s degree or above; • Possess competency certificates such as Software Evaluator and Database System Engineer; 3. Familiar with national standards for software quality models and testing including national standard GB/T 25000.51, with practical experience in acceptance testing for large-scale government informatization projects. 6. Facilities and Personnel Provided by the Client The Client shall provide the following necessary support for smooth project implementation: relevant project documents, reports, annual work plans and other materials; dedicated staff assigned to liaise with the service provider for the implementation of relevant work.
Exact source section
Total investment for this project amounts to RMB 420,000. 3.1 Scope of Service Recipients The scope of services of this project covers special security evaluation services and acceptance evaluation services for four information-based sub-projects, specifically as follows: 1.Full-chain food traceability platform project with "ShangMa Su" for key food sectors (categories); 2.Guangdong Food Safety "Internet-based Visualization Kitchen" system construction project; 3.Upgrading, renovation and operation project of the real-time emergency dispatching command system; 4.Capacity improvement project for food-related personnel in the market supervision field. 3.2 Service Content 3.2.1 Special Security Evaluation Service Before the system launch on the Guangdong E-Government Cloud or domestic cloud, the service provider shall conduct a pre-launch security evaluation of the system. The security evaluation institution shall conduct non-destructive penetration testing on the system by simulating hacker attack methods. The objective is to attempt system intrusion and obtain system control privileges, and deliver a report to the Client documenting the intrusion process and details. The evaluation shall focus on networks, hosts, applications, data and the overall system, to assess whether the system has adequate capabilities of information security protection, meets the safety management and control requirements of the industry and competent authorities, can continuously provide secure, stable and efficient business support, and can safeguard sensitive information and public privacy. 3.2.2 Acceptance Evaluation Services Before the final project acceptance, the service provider shall conduct pre-acceptance evaluation and compliance inspection for the informatization service project to strictly control project quality, so as to ensure that all indicators fully comply with the contract, requirement specification and construction specifications. The scope mainly includes functional testing, performance efficiency testing, information security testing, compatibility testing, reliability testing, usability testing, maintainability testing, portability testing, and documentation review, among others. 3.3 Service Period The service period shall commence on the date of contract signing and end on the project closure date (March 31, 2029). The specific service schedule shall be implemented in phases in accordance with the system launch and acceptance progress of the four informatization sub-projects. 4. Deliverables, Review and Acceptance 4.1 Deliverables The deliverables required under this project are set out below: No. Report Name Submission Timing / Stage 1 Project Start Date Start date for acceptance testing: subject to the project’s preliminary acceptance date; Start date for security testing: subject to the system launch date. 2 Acceptance Evaluation Plan To be submitted within 10 working days after receipt of project documents. 3 Acceptance Test Issue Report To be submitted within 5 working days upon completion of the first round of testing. 4 Acceptance Evaluation Report To be submitted within 5 working days upon completion of regression testing. 5 Security Evaluation Plan To be submitted within 10 working days after receipt of project documents. 6 Security Evaluation Issue Report To be submitted within 5 working days upon completion of the first round of testing. 7 Security Evaluation Report To be submitted within 5 working days upon completion of regression testing. 4.2 Deliverable Review and Acceptance After the Project Office reviews and approves submitted deliverable reports, the service provider shall cooperate with the Project Office to submit documents required for World Bank review, and the stage deliverables shall only be formally finalized upon receiving a no-objection opinion from the World Bank. All deliverables shall fully comply with the service requirements specified in this TOR, with standardized format, complete content and authentic, accurate data. 5.Institutional and Personnel Qualification Requirements 5.1 Institutional Qualifications 5.1.1 Qualification Requirements for the Service Provider The service provider undertaking both special security evaluation and acceptance evaluation services shall hold valid qualifications: either the Certificates of Accreditation for Testing Laboratories (including CNAS Laboratory Accreditation Certificates) issued by the China National Accreditation Service for Conformity Assessment (CNAS), or the Certificate of Metrology Accreditation (CMA) issued by market supervision authorities at or above the provincial level. The service provider shall have independently completed no fewer than 5 projects of special security evaluation and acceptance evaluation services within the past three years. Such track records shall cover government informatization, software platform development, system integration, cybersecurity and other relevant categories, which can fully demonstrate the provider’s comprehensive service capacity to conduct pre-launch security evaluation and final quality control for complex informatization projects. 5.2 Personnel Qualifications To ensure the quality of the special security evaluation service and acceptance evaluation service under this project, a dedicated service team shall be assigned. The job responsibilities, academic qualifications, working experience and professional competency requirements for each role are set out as follows: No. Team Role Number of Staff Job Responsibilities Qualification Requirements 1 Project Manager 1 Overall project life-cycle coordination, resource allocation, cross-department communication; develop detailed evaluation implementation plan and schedule; fully control the quality of all deliverables including project start report, test plan and final evaluation report; conduct daily communication and reporting with the Client and supervision unit; organize project acceptance and assist in completing relevant filing work. 1. Bachelor's degree or above; 2. Possess competency certificate for informatization project management. 3.Over 10 years of working experience in special security evaluation and acceptance evaluation services. 2 Project Technical Leader 1 Take the lead in developing the Acceptance Test Plan and technical plan for special security evaluation; provide technical oversight for on-site evaluation work; conduct in-depth analysis and risk grading for complex vulnerabilities identified during penetration testing and functional testing; propose practical technical solutions for rectification and hardening against system defects; review the objectivity, accuracy and logical rigor of test reports. 1. Bachelor's degree or above; 2. Possess competency certificates in software, cybersecurity and related fields. 3.Over 10 years of working experience in cybersecurity and software acceptance. 3 Special Security Evaluation Team 2 Responsible for pre-launch special security evaluation of the system; conduct non-destructive penetration testing and vulnerability scanning on networks, hosts, applications, data and the overall system by simulating hacker attacks with professional tools; assess whether the system meets the safety management and control requirements of the industry and competent authorities; prepare the Security Test Report and Rectification Recommendations, and guide and cooperate with the rectification party to complete security hardening. 1. Bachelor’s degree or above; 2. Possess national competency certificates in registered penetration testing, information security, network and related fields; 3. Familiar with mainstream penetration testing tools and have practical experience in security evaluation under the Guangdong E-Government Cloud or domestic cloud environment. 4 Acceptance Evaluation Team 2 Responsible for pre-acceptance evaluation and compliance inspection of the project; conduct functional testing, performance efficiency testing, information security testing, compatibility testing, reliability testing, usability testing, maintainability testing, portability testing, and documentation review in strict accordance with the requirement specification; record issues identified during testing process and prepare the Issue Report; summarize test results and prepare standardized Acceptance Test Report to ensure all indicators comply with construction standards. • Bachelor’s degree or above; • Possess competency certificates such as Software Evaluator and Database System Engineer; 3. Familiar with national standards for software quality models and testing including national standard GB/T 25000.51, with practical experience in acceptance testing for large-scale government informatization projects. 6. Facilities and Personnel Provided by the Client The Client shall provide the following necessary support for smooth project implementation: relevant project documents, reports, annual work plans and other materials; dedicated staff assigned to liaise with the service provider for the implementation of relevant work.
Source / meaning
Official record metadata: USD 60,900سامانه رسمی مناقصات تدارکاتی بانک جهانی — official notice / tender document
Source / meaning
Total investment for this project amounts to RMB 420,000.سامانه رسمی مناقصات تدارکاتی بانک جهانی — official notice / tender document
Source / meaning
The total estimated amount for this project is RMB 0.42 million.سامانه رسمی مناقصات تدارکاتی بانک جهانی — official notice / tender document
Source / meaning
The service provider shall have independently completed no fewer than 5 projects of special security evaluation and acceptance evaluation services within the past three years.سامانه رسمی مناقصات تدارکاتی بانک جهانی — official notice / tender document
Source / meaning
5.2 Personnel Qualificationsسامانه رسمی مناقصات تدارکاتی بانک جهانی — official notice / tender document
Source / meaning
More than 10 years of experience in specialized security assessment and acceptance assessment services.سامانه رسمی مناقصات تدارکاتی بانک جهانی — official notice / tender document
Source / meaning
More than 10 years of working experience in network information security and software acceptance.سامانه رسمی مناقصات تدارکاتی بانک جهانی — official notice / tender document
Source / meaning
3.Over 10 years of working experience in special security evaluation and acceptance evaluation services.سامانه رسمی مناقصات تدارکاتی بانک جهانی — official notice / tender document
Source / meaning
3.Over 10 years of working experience in cybersecurity and software acceptance.سامانه رسمی مناقصات تدارکاتی بانک جهانی — official notice / tender document
Extraction covers only the accessible source. Linked TORs and later addenda are not verified unless their text has been retrieved; a missing field never means no requirement.
Shortlisting / qualification criteria
Organisation history and structure
Not found among the extracted criteriaNo explicit requirement in this category appears among the criteria extracted from the currently available official text. Verify the complete notice, TOR and addenda.
Technical and managerial capability
1 explicit requirement(s)shortlisting criteria are: the overall competence and strength of the Consultant, quality control and project management capabilities, understanding of the assignment, relevant experience and past performance, proposed team composition, preliminary work plan, and a brief technical approach.
Prepare a matrix linking each required service to a reference assignment, firm role, delivered output and evidence, plus delivery organization and resources.
Preparation advice, not an additional employer requirement. Submit only the documents and formats required by the notice/TOR for this stage.Source excerpt for this employer criterion
shortlisting criteria are: the overall competence and strength of the Consultant, quality control and project management capabilities, understanding of the assignment, relevant experience and past performance, proposed team composition, preliminary work plan, and a brief technical approach.Source location: سامانه رسمی مناقصات تدارکاتی بانک جهانی — shortlisting / qualification criteria
Similar experience
Not found among the extracted criteriaNo explicit requirement in this category appears among the criteria extracted from the currently available official text. Verify the complete notice, TOR and addenda.
Key personnel
2 explicit requirement(s)shortlisting criteria are: the overall competence and strength of the Consultant, quality control and project management capabilities, understanding of the assignment, relevant experience and past performance, proposed team composition, preliminary work plan, and a brief technical approach. Key Experts will be evaluated at the shortlisting stage. (VII) Contents of this Consultation a.Expression of interest in undertaking the supervision services for this project; b.Agency profile and core advantages;
Map each stated role to its CV, qualifications, references and availability; verify the required format and submission stage.
Preparation advice, not an additional employer requirement. Submit only the documents and formats required by the notice/TOR for this stage.Source excerpt for this employer criterion
shortlisting criteria are: the overall competence and strength of the Consultant, quality control and project management capabilities, understanding of the assignment, relevant experience and past performance, proposed team composition, preliminary work plan, and a brief technical approach. Key Experts will be evaluated at the shortlisting stage. (VII) Contents of this Consultation a.Expression of interest in undertaking the supervision services for this project; b.Agency profile and core advantages;Source location: سامانه رسمی مناقصات تدارکاتی بانک جهانی — shortlisting / qualification criteria
f.Proposed core team (including resume summaries of the Project Manager and key experts). (VIII) Submission Materials a."Expression of Interest Letter" (or "Feedback Letter") submitted by the supervision service agency; b.Agency profile; c.Summary of project performance records (specifying the project name, client, service content, and service period);
Map each stated role to its CV, qualifications, references and availability; verify the required format and submission stage.
Preparation advice, not an additional employer requirement. Submit only the documents and formats required by the notice/TOR for this stage.Source excerpt for this employer criterion
f.Proposed core team (including resume summaries of the Project Manager and key experts). (VIII) Submission Materials a."Expression of Interest Letter" (or "Feedback Letter") submitted by the supervision service agency; b.Agency profile; c.Summary of project performance records (specifying the project name, client, service content, and service period);Source location: سامانه رسمی مناقصات تدارکاتی بانک جهانی — shortlisting / qualification criteria
Eligibility and legal requirements
1 explicit requirement(s)b. neither a Consultant (including personnel and sub-consultants), nor an affiliate (that directly or indirectly controls, is controlled by, or is under common control with that Consultant), shall be hired for any assignment that, by its nature, creates a conflict of interest with another assignment of the Consultant;
Prepare a declaration and records of ownership, affiliations and relevant prior assignments for conflict review.
Preparation advice, not an additional employer requirement. Submit only the documents and formats required by the notice/TOR for this stage.Source excerpt for this employer criterion
b. neither a Consultant (including personnel and sub-consultants), nor an affiliate (that directly or indirectly controls, is controlled by, or is under common control with that Consultant), shall be hired for any assignment that, by its nature, creates a conflict of interest with another assignment of the Consultant;Source location: سامانه رسمی مناقصات تدارکاتی بانک جهانی — shortlisting / qualification criteria
Company financial capacity
Not found among the extracted criteriaNo explicit requirement in this category appears among the criteria extracted from the currently available official text. Verify the complete notice, TOR and addenda.
Other employer-specific criteria
1 explicit requirement(s)a. a firm that has been engaged by the Borrower to provide Goods, Works, or Non-Consulting Services for a project (or an affiliate that directly or indirectly controls, is controlled by, or is under common control with that firm), shall be disqualified from providing Consulting Services resulting from, or directly related to, those Goods, Works, or Non-Consulting Services.
Map this exact clause to verifiable evidence and confirm format, issuer and validity with the employer documents; an unspecified document is not an employer requirement.
Preparation advice, not an additional employer requirement. Submit only the documents and formats required by the notice/TOR for this stage.Source excerpt for this employer criterion
a. a firm that has been engaged by the Borrower to provide Goods, Works, or Non-Consulting Services for a project (or an affiliate that directly or indirectly controls, is controlled by, or is under common control with that firm), shall be disqualified from providing Consulting Services resulting from, or directly related to, those Goods, Works, or Non-Consulting Services.Source location: سامانه رسمی مناقصات تدارکاتی بانک جهانی — shortlisting / qualification criteria
Complete retrieved official text
REQUEST FOR EXPRESSIONS OF INTEREST INFORMATION TECHNOLOGY SPECIALLIZED SECURITY ASSESSMENT SERVICE AND ACCEPTANCE ASSESSMENT SERVICE for China Food Safety Improvement Project Guangdong Agricultural Product Quality and Safety Improvement (Demonstration) Project Country: People's Republic of China Name of Project: China Food Safety Improvement Project Loan No.: IBRD-92130 Assignment Title: Guangdong Agricultural Product Quality and Safety Improvement (Demonstration) Project Information Technology Third-Party Service Package III (Speciallized Security Assessment Service and Acceptance Assessment Service) Reference No.: GD-FSS-GAMR-CS14 The Guangdong Administration for Market Regulation has received financing from the World Bank toward the cost of the China Food Safety Improvement Project Guangdong Agricultural Product Quality and Safety Improvement (Demonstration) Project, and intends to apply part of the proceeds for consulting services. The total estimated amount for this project is RMB 0.42 million. (I) Scope of Services The service scope of this project covers specialized security assessment services and acceptance assessment services for four informatization sub-projects, specifically including: • The "Scan-to-Trace" Full-Chain Traceability Platform Project for Food in Key Fields (Categories); • The "Yue-Shi-An Internet Plus Open Kitchens" System Construction Project; • The Upgrade, Renovation, and Operation Project of the Emergency Real-Time Dispatch and Command System; • The Capacity Building Project for Food-Related Personnel in Market Regulation. (II) Service Content 1. Specialized Security Assessment Services Before the system is launched on the provincial government cloud or domestic cloud, the service agency shall conduct a pre-launch security assessment. The security assessment agency will simulate hacker attack methods to perform non-destructive offensive testing on the system. The objective is to attempt to intrude into the system and obtain system control, and then generate a report detailing the intrusion process and specifics for the user. The assessment will focus on the network, host, application, data, and the overall system to evaluate whether the system possesses sufficient information security protection capabilities, meets the security control requirements of the industry and competent authorities, can continuously provide secure, stable, and efficient business support, and can guarantee the security of sensitive information and public privacy. 2. Acceptance Assessment Services Before the final project acceptance, the service agency shall conduct pre-acceptance assessments and compliance checks for the informatization services to strictly manage project quality and ensure that all indicators comply with design standards and construction specifications such as the contract and requirement specifications. This mainly includes: functional testing, performance efficiency testing, information security testing, compatibility testing, reliability testing, usability testing, maintainability testing, portability testing, and document review. (III) Service Period The service period for this project shall commence from the date of contract signing and continue until the project closing date (March 31, 2029). The specific service timeline will be implemented in phases based on the system launch schedule of the four informatization projects. (IV) Deliverables The deliverables required for this project are as follows: No. Report Name Submission Date/Phase 1 Mobilization Time Acceptance Assessment Mobilization Time: Subject to the time of preliminary project acceptance; Security Assessment Mobilization Time: Subject to the system launch time. 2 Acceptance Assessment Plan Submitted within 10 working days after receiving the project materials. 3 Acceptance Testing Issue Report Submitted within 5 working days after the completion of the first round of testing. 4 Acceptance Assessment Report Submitted within 5 working days after the completion of regression testing. 5 Security Assessment Plan Submitted within 10 working days after receiving the project materials. 6 Security Assessment Issue Report Submitted within 5 working days after the completion of the first round of testing. 7 Security Assessment Report Submitted within 5 working days after the completion of regression testing. Upon receiving the deliverable reports submitted by the assessment service agency, the Project Management Office (PMO) shall review them. For deliverable documents that are required to be submitted to the World Bank for review according to regulations, the assessment service agency shall assist the PMO in completing the submission. The phased deliverables shall be officially considered closed only after obtaining the World Bank's "no objection." All deliverable reports must fully align with the service content specified in this Terms of Reference (TOR). They must be standardized in format, comprehensive in content, and authentic and accurate in data. V. Agency Qualification Requirements Service agencies undertaking the two types of services—specialized security assessment and acceptance assessment—must possess valid qualifications. They must hold either the Inspection Body Accreditation Certificate (including the CNAS Laboratory Accreditation Certificate) issued by the China National Accreditation Service for Conformity Assessment (CNAS), or the Inspection and Testing Agency Qualification Accreditation Certificate (CMA) issued by market regulation departments at or above the provincial level. Within the past three years, the service agency must have independently undertaken no fewer than five specialized security assessment and acceptance assessment service projects. The relevant performance records must cover related types such as government informatization, software platform construction, system integration, and network security. These records must sufficiently demonstrate the agency's comprehensive service capability in conducting pre-launch security assessments and final acceptance quality control for complex informatization projects. Note: The service performance records refer to contracts signed on or after January 1, 2023. (VI) Personnel Qualification Requirements To ensure the service quality of the specialized security assessment and acceptance assessment services for this project, a dedicated full-time service team must be established. The specific job responsibilities, educational background, years of experience, and professional competency requirements for each position are as follows: No. Expert Position Qty. Responsibilities Qualifications 1 Project Manager 1 Responsible for overall management, resource allocation, and cross-departmental coordination throughout the entire project lifecycle. Formulate detailed assessment implementation plans and schedules. Comprehensively control the quality of all deliverables, including the mobilization report, testing plans, and final assessment reports. Responsible for daily communication and reporting with the purchaser and the supervision unit. Organize project acceptance and assist in completing relevant filing (record-keeping) work. 1. Bachelor's degree or above; 2. Possess competency certificates in informatization project management; 3. More than 10 years of experience in specialized security assessment and acceptance assessment services. 2 Technical Director 1 Take the lead in drafting the "Acceptance Testing Plan" and specialized security assessment technical plans. Provide technical supervision for on-site assessment work, conduct in-depth analysis and risk grading of complex hidden dangers found during penetration testing and functional testing. Provide feasible technical solutions for rectification and reinforcement for existing system defects. Review the objectivity, accuracy, and logical rigor of the testing reports. 1. Bachelor's degree or above; 2. Possess competency certificates in software, network, and information security; 3. More than 10 years of working experience in network information security and software acceptance. 3 Specialized Security Assessment Task Force 2 Responsible for specialized security assessments before system launch. Utilize professional tools to simulate hacker attacks, conducting non-destructive penetration testing and vulnerability scanning on the network, host, application, data, and overall system. Evaluate whether the system meets the security control requirements of the industry and competent authorities. Draft the "Security Testing Report" and "Rectification Suggestions," and guide and assist the rectification party in completing security reinforcement. 1. Bachelor's degree or above; 2. Possess competency certificates in national registered penetration testing, information security, and network; 3. Familiar with mainstream penetration testing tools, with practical experience in security assessment under government cloud/domestic cloud environments. 4 Acceptance Assessment Task Force 2 Responsible for assessments and compliance checks prior to final project acceptance. Strictly follow the requirement specifications to conduct functional testing, performance efficiency testing, compatibility testing, reliability testing, usability testing, maintainability testing, portability testing, and document review. Record issues during the testing process and draft the "Issue Report." Summarize test results and draft a standardized "Acceptance Testing Report" to ensure all indicators meet construction standards. 1. Bachelor's degree or above; 2. Possess competency certificates such as Software Testing Engineer and Database System Engineer; 3. Familiar with software quality models and national testing standards such as GB/T 25000.51, with practical experience in acceptance testing for large-scale government informatization projects. The detailed Terms of Reference (TOR) for the assignment are attached to this request for expressions of interest. The Guangdong Administration for Market Regulation now invites eligible consulting firms (“Consultants”) to indicate their interest in providing the Services. Interested Consultants should provide information demonstrating that they have the required qualifications and relevant experience to perform the Services. The shortlisting criteria are: the overall competence and strength of the Consultant, quality control and project management capabilities, understanding of the assignment, relevant experience and past performance, proposed team composition, preliminary work plan, and a brief technical approach. Key Experts will be evaluated at the shortlisting stage. (VII) Contents of this Consultation a.Expression of interest in undertaking the supervision services for this project; b.Agency profile and core advantages; c.List of project performance records; d.Key points of the preliminary work plan and work schedule; e.Preliminary staffing plan; f.Proposed core team (including resume summaries of the Project Manager and key experts). (VIII) Submission Materials a."Expression of Interest Letter" (or "Feedback Letter") submitted by the supervision service agency; b.Agency profile; c.Summary of project performance records (specifying the project name, client, service content, and service period); d.Simplified proposal (briefly outlining key points; a detailed proposal is not required); e.Preliminary work schedule; f.Key team experts (personnel profiles must be provided); g.Any other materials deemed necessary by the supervision service agency. Note: All the above materials must be stamped with the official seal of the consulting agency. Consultants shall not be hired for any assignment that would be in conflict with their prior or current obligations to other clients, or that may place them in a position of being unable to carry out the assignment in the best interests of the Borrower. Without limitation on the generality of the foregoing, Consultants shall not be hired under the circumstances set forth below : a. a firm that has been engaged by the Borrower to provide Goods, Works, or Non-Consulting Services for a project (or an affiliate that directly or indirectly controls, is controlled by, or is under common control with that firm), shall be disqualified from providing Consulting Services resulting from, or directly related to, those Goods, Works, or Non-Consulting Services. This provision does not apply to the various firms (Consultants, contractors, or suppliers), which together are performing the contractor’s obligations under a turnkey or design and build contract; a firm that has been engaged by the Borrower to provide Consulting Services for the preparation or implementation of a project (or an affiliate that directly or indirectly controls, is controlled by, or is under common control with that Consulting firm), shall be disqualified from subsequently providing Goods, Works, or Non-Consulting Services resulting from, or directly related to those Consulting Services. This provision does not apply to the various firms (Consultants, contractors, or suppliers), which together are performing the contractor’s obligations under a turnkey or design and build contract; b. neither a Consultant (including personnel and sub-consultants), nor an affiliate (that directly or indirectly controls, is controlled by, or is under common control with that Consultant), shall be hired for any assignment that, by its nature, creates a conflict of interest with another assignment of the Consultant; c. Consultants (including their experts and other personnel, and sub-consultants), that have a close business or family relationship with a professional staff of the Borrower, or of the project implementing agency, or of a recipient of a part of the Bank’s financing, or any other party representing or acting on behalf of the Borrower, that is directly or indirectly involved in any part of: i. the preparation of the ToR for the assignment; ii. the selection process for the contract; or iii. the supervision of the contract; may not be awarded a contract, unless the conflict stemming from this relationship has been resolved in a manner acceptable to the Bank throughout the selection process and the execution of the contract. Consultants may associate with other firms to enhance their qualifications, but should indicate clearly whether the association is in the form of a joint venture and/or a sub-consultancy. In the case of a joint venture, all the partners in the joint venture shall be jointly and severally liable for the entire contract, if selected. A Consultant will be selected in accordance with the CQS method set out in the Procurement Regulations. Further information can be obtained at the address below during office hours. Office hours are from 09:00 to 17:00 on working days from September 12 to September 29, 2026 Expressions of interest must be delivered in a written form to the address below (in person, or by mail, or by fax, or by e-mail) by 09:00 on September 30, 2026 . Tender Agency: China International Tendering Co., Ltd. Attn: Zhang Zhi, Guo Hujun Title: Project Manager Address: Room 2003B, South Tower, Jinbin Tengyue Building, Huaxia Road No. 49-1, Tianhe District, Guangzhou, Guangdong Province, China Postal Code: 51000 Tel.: 010-81168424; 010-81168460 E-mail: zhangzhi5@cgci.gt.cn; guohujun@gt.cn Employer: Guangdong Administration for Market Regulation Attn: Chen Lin Title: Special Cadre, World Bank Loan Project Office Address: No. 363 West Huangpu Avenue, Tianhe District, Guangzhou, Guangdong Province, China Tel.: 020-38835493 E-mail: gdsjj_xietiaoyingji@gd.gov.cn ANNEX: DETAILED TERMS OF REFERENCE (TOR) TERMS OF REFERENCE In order to ensure the effective implementation of PackageThird-Party Informatization Services (‌Special Security Evaluation and Acceptance Evaluation Services) under the above-mentioned project, and to achieve the targeted objectives of project information technology development, the Guangdong Administration for Market Regulation intends to select and engage qualified service institutions through public procurement to carry out the implementation of this project. 1. Project Background and Overview The World Bank-financed China Food Safety Improvement Project took effect on March 21, 2024, with an implementation period ending on March 31, 2029. It aims to comprehensively enhance national and local modern food safety governance capacity. As a key implementing entity of this project in Guangdong Province, the Guangdong Administration for Market Regulation intends to apply for a World Bank loan of USD10,000,000. It will provide targeted support for the achievement of project objectives through the implementation of six core sub-projects, as detailed below: First, develop a full-chain traceability platform with "ShangMa Su" for food in key sectors, which consists of 15 functional modules and 359 functional points to realize whole-process traceability and risk early warning. Second, build the intelligent supervision system of "Internet-based Visualization Kitchen" of Guangdong Food Safety to realize intelligent video supervision covering canteens of elderly care institutions, campuses and other scenarios. Third, upgrade and renovate the real-time emergency dispatching command system, and improve the emergency response mechanism for food safety incidents. Fourth, launch a capacity improvement program for food-related personnel in the market supervision field, including the development of a learning and assessment system, the production of 75 course videos, and the organization of professional skills competitions. Fifth, establish and promote a high-quality food standard system, develop no fewer than 30 standards within two years, and carry out corresponding quality monitoring work. Sixth, provide full-process professional consulting services for project implementation. To ensure the high-quality implementation of the above contents, relevant practices of other World Bank projects will be referenced to optimize procurement management and enhance the overall efficiency of service coordination. In the subsequent actual procurement process and without changing the total project budget, the special security evaluation and acceptance evaluation services of four sub-projects - namely, the full-chain food traceability platform project with“ShangMa Su”for key food sectors (categories), the Guangdong Food Safety “Internet-based Visualization Kitchen” system construction project, the upgrading, renovation and operation project of the real-time emergency dispatching command system, and the capacity improvement project for food-related personnel in the market supervision field - will be integrated into one single packaged project, so as to guarantee the smooth achievement of project objectives. 2.Project Objectives Centered on the core objective of comprehensively improving the modern governance capacity of food safety, this project integrates the full-chain traceability platform with "ShangMa Su", the intelligent supervision system of "Internet-based Visualization Kitchen", the real-time emergency dispatching command system, and capacity improvement for food-related personnel in the market supervision field. It aims to establish a closed-loop full-chain management mechanism covering risk identification, early-warning response and disposal, so as to provide data foundation and institutional guarantee for scientifically calculating outcome indicators such as“proportion of early-warnings for which mitigation measures have been activated". Meanwhile, the learning and assessment system for capacity improvement program for food-related personnel enables systematic training for supervisors and quantifies the participation rate of female supervisor. The core objectives are to carry out the non-destructive security evaluation by adopting methods such as simulated hacker attacks before system launch to comprehensively assess the protection capabilities of network, host, application and other layers, so as to ensure compliance with industrial safety management and control requirements and protect the security of sensitive information and public privacy; conduct multi-dimensional evaluation and compliance inspection covering functionality, performance, information security and compatibility before final project acceptance to strictly control project quality, so as to ensure that all indicators fully comply with the contract, requirement specification and construction specifications. This provides a solid guarantee for the smooth acceptance and safe operation of the project, ensures the collection, accounting and reporting of all indicator data conform to World Bank standards, and facilitates the efficient implementation of the World Bank project. 3. Scope of Services Total investment for this project amounts to RMB 420,000. 3.1 Scope of Service Recipients The scope of services of this project covers special security evaluation services and acceptance evaluation services for four information-based sub-projects, specifically as follows: 1.Full-chain food traceability platform project with "ShangMa Su" for key food sectors (categories); 2.Guangdong Food Safety "Internet-based Visualization Kitchen" system construction project; 3.Upgrading, renovation and operation project of the real-time emergency dispatching command system; 4.Capacity improvement project for food-related personnel in the market supervision field. 3.2 Service Content 3.2.1 Special Security Evaluation Service Before the system launch on the Guangdong E-Government Cloud or domestic cloud, the service provider shall conduct a pre-launch security evaluation of the system. The security evaluation institution shall conduct non-destructive penetration testing on the system by simulating hacker attack methods. The objective is to attempt system intrusion and obtain system control privileges, and deliver a report to the Client documenting the intrusion process and details. The evaluation shall focus on networks, hosts, applications, data and the overall system, to assess whether the system has adequate capabilities of information security protection, meets the safety management and control requirements of the industry and competent authorities, can continuously provide secure, stable and efficient business support, and can safeguard sensitive information and public privacy. 3.2.2 Acceptance Evaluation Services Before the final project acceptance, the service provider shall conduct pre-acceptance evaluation and compliance inspection for the informatization service project to strictly control project quality, so as to ensure that all indicators fully comply with the contract, requirement specification and construction specifications. The scope mainly includes functional testing, performance efficiency testing, information security testing, compatibility testing, reliability testing, usability testing, maintainability testing, portability testing, and documentation review, among others. 3.3 Service Period The service period shall commence on the date of contract signing and end on the project closure date (March 31, 2029). The specific service schedule shall be implemented in phases in accordance with the system launch and acceptance progress of the four informatization sub-projects. 4. Deliverables, Review and Acceptance 4.1 Deliverables The deliverables required under this project are set out below: No. Report Name Submission Timing / Stage 1 Project Start Date Start date for acceptance testing: subject to the project’s preliminary acceptance date; Start date for security testing: subject to the system launch date. 2 Acceptance Evaluation Plan To be submitted within 10 working days after receipt of project documents. 3 Acceptance Test Issue Report To be submitted within 5 working days upon completion of the first round of testing. 4 Acceptance Evaluation Report To be submitted within 5 working days upon completion of regression testing. 5 Security Evaluation Plan To be submitted within 10 working days after receipt of project documents. 6 Security Evaluation Issue Report To be submitted within 5 working days upon completion of the first round of testing. 7 Security Evaluation Report To be submitted within 5 working days upon completion of regression testing. 4.2 Deliverable Review and Acceptance After the Project Office reviews and approves submitted deliverable reports, the service provider shall cooperate with the Project Office to submit documents required for World Bank review, and the stage deliverables shall only be formally finalized upon receiving a no-objection opinion from the World Bank. All deliverables shall fully comply with the service requirements specified in this TOR, with standardized format, complete content and authentic, accurate data. 5.Institutional and Personnel Qualification Requirements 5.1 Institutional Qualifications 5.1.1 Qualification Requirements for the Service Provider The service provider undertaking both special security evaluation and acceptance evaluation services shall hold valid qualifications: either the Certificates of Accreditation for Testing Laboratories (including CNAS Laboratory Accreditation Certificates) issued by the China National Accreditation Service for Conformity Assessment (CNAS), or the Certificate of Metrology Accreditation (CMA) issued by market supervision authorities at or above the provincial level. The service provider shall have independently completed no fewer than 5 projects of special security evaluation and acceptance evaluation services within the past three years. Such track records shall cover government informatization, software platform development, system integration, cybersecurity and other relevant categories, which can fully demonstrate the provider’s comprehensive service capacity to conduct pre-launch security evaluation and final quality control for complex informatization projects. 5.2 Personnel Qualifications To ensure the quality of the special security evaluation service and acceptance evaluation service under this project, a dedicated service team shall be assigned. The job responsibilities, academic qualifications, working experience and professional competency requirements for each role are set out as follows: No. Team Role Number of Staff Job Responsibilities Qualification Requirements 1 Project Manager 1 Overall project life-cycle coordination, resource allocation, cross-department communication; develop detailed evaluation implementation plan and schedule; fully control the quality of all deliverables including project start report, test plan and final evaluation report; conduct daily communication and reporting with the Client and supervision unit; organize project acceptance and assist in completing relevant filing work. 1. Bachelor's degree or above; 2. Possess competency certificate for informatization project management. 3.Over 10 years of working experience in special security evaluation and acceptance evaluation services. 2 Project Technical Leader 1 Take the lead in developing the Acceptance Test Plan and technical plan for special security evaluation; provide technical oversight for on-site evaluation work; conduct in-depth analysis and risk grading for complex vulnerabilities identified during penetration testing and functional testing; propose practical technical solutions for rectification and hardening against system defects; review the objectivity, accuracy and logical rigor of test reports. 1. Bachelor's degree or above; 2. Possess competency certificates in software, cybersecurity and related fields. 3.Over 10 years of working experience in cybersecurity and software acceptance. 3 Special Security Evaluation Team 2 Responsible for pre-launch special security evaluation of the system; conduct non-destructive penetration testing and vulnerability scanning on networks, hosts, applications, data and the overall system by simulating hacker attacks with professional tools; assess whether the system meets the safety management and control requirements of the industry and competent authorities; prepare the Security Test Report and Rectification Recommendations, and guide and cooperate with the rectification party to complete security hardening. 1. Bachelor’s degree or above; 2. Possess national competency certificates in registered penetration testing, information security, network and related fields; 3. Familiar with mainstream penetration testing tools and have practical experience in security evaluation under the Guangdong E-Government Cloud or domestic cloud environment. 4 Acceptance Evaluation Team 2 Responsible for pre-acceptance evaluation and compliance inspection of the project; conduct functional testing, performance efficiency testing, information security testing, compatibility testing, reliability testing, usability testing, maintainability testing, portability testing, and documentation review in strict accordance with the requirement specification; record issues identified during testing process and prepare the Issue Report; summarize test results and prepare standardized Acceptance Test Report to ensure all indicators comply with construction standards. • Bachelor’s degree or above; • Possess competency certificates such as Software Evaluator and Database System Engineer; 3. Familiar with national standards for software quality models and testing including national standard GB/T 25000.51, with practical experience in acceptance testing for large-scale government informatization projects. 6. Facilities and Personnel Provided by the Client The Client shall provide the following necessary support for smooth project implementation: relevant project documents, reports, annual work plans and other materials; dedicated staff assigned to liaise with the service provider for the implementation of relevant work.
Document, security and collaboration conditions
Consortium and local-partner condition
The official text contains consortium or joint-venture conditions, but the currently available wording does not conclusively establish whether that structure is permitted or mandatory.
View 2 exact source clause(s)
b. neither a Consultant (including personnel and sub-consultants), nor an affiliate (that directly or indirectly controls, is controlled by, or is under common control with that Consultant), shall be hired for any assignment that, by its nature, creates a conflict of interest with another assignment of the Consultant;Locator: سامانه رسمی مناقصات تدارکاتی بانک جهانی — shortlisting / qualification criteria
Consultants (including their experts and other personnel, and sub-consultants), that have a close business or family relationship with a professional staff of the Borrower, or of the project implementing agency, or of a recipient of a part of the Bank’s financing, or any other party representing or acting on behalf of the Borrower, that is directly or indirectly involved in any part of: i. the preparation of the ToR for the assignment; ii. the selection process for the contract; or iii. the supervision of the contract; may not be awarded a contract, unless the conflict stemming from this relationship has been resolved in a manner acceptable to the Bank throughout the selection process and the execution of the contractLocator: سامانه رسمی مناقصات تدارکاتی بانک جهانی — shortlisting / qualification criteria
Unstated means “not found in the official text currently available to FANAB”, not “not required”. Always verify the complete notice, TOR and addenda.
