FreeTender
Accepting bidseoiChina

Guangdong Agricultural Product Quality and Safety Improvement (Demonstration) Project Information Technology Service Package II (Cybersecurity Level Protection Assessment Service and Commercial Cryptography Application Security Evaluation Service)

Issued by China International Tendering Co., Ltd. · via World Bank — Procurement Notices

Published
10 Sept 2026
Closes
30 Sept 2026
Reference
GD-FSS-GAMR-CS13
Location
China
Sector
IT & Telecom
Type
consultancy

Details

REQUEST FOR EXPRESSIONS OF INTEREST INFORMATION TECHNOLOGY CYBERSECURITY LEVEL PROTECTION ASSESSMENT SERVICE AND COMMERCIAL CRYPTOGRAPHY APPLICATION SECURITY EVALUATION SERVICE for China Food Safety Improvement Project Guangdong Agricultural Product Quality and Safety Improvement (Demonstration) Project

Country: People's Republic of China

Name of Project: China Food Safety Improvement Project

Loan No.: IBRD-92130

Assignment Title: Guangdong Agricultural Product Quality and Safety Improvement (Demonstration) Project Information Technology Third-Party Service Package II (Cybersecurity Level Protection Assessment Service and Commercial Cryptography Application Security Evaluation Service)

Reference No.: GD-FSS-GAMR-CS13

The Guangdong Administration for Market Regulation has received financing from the World Bank toward the cost of the China Food Safety Improvement Project Guangdong Agricultural Product Quality and Safety Improvement (Demonstration) Project, and intends to apply part of the proceeds for consulting services. The total estimated amount for this project is RMB 0.56 million. (I) Scope of Service The service scope of this project covers the Cybersecurity Level Protection Assessment and Commercial Cryptography Application Security Assessment services required for four informatization projects, specifically including: The "Scan-to-Trace" Full-Chain Traceability Platform Project for Food in Key Fields (Categories); The "Yue-Shi-An Internet Plus Open Kitchens" System Construction Project; The Upgrade, Renovation, and Operation Project of the Emergency Real-Time Dispatch and Command System; The Capacity Building Project for Food-Related Personnel in Market Regulation.

(II) Service Contents

1. Cybersecurity Level Protection Assessment Services

Based on the assessment results of security technology and security management controls, as well as the overall system assessment, the service agency shall conduct a comprehensive assessment of the information system in accordance with the corresponding level standards and provide relevant security review opinions. This specifically includes two aspects: First, security control assessment, which primarily evaluates the implementation and configuration of basic security controls required by the cybersecurity level protection standards within the information system. Second, overall system assessment, which primarily analyzes the overall security of the information system. The security control assessment serves as the foundation for the overall security assessment of the information system.

2. Commercial Cryptography Application Security Assessment Services

The service agency shall provide security assessment services for systems upgraded with domestic cryptography. For the upgraded national cryptographic systems, the agency shall formulate an assessment plan, conduct the assessment, propose rectification opinions, and track the rectification progress in accordance with national specifications, thereby providing a basis for project acceptance. Through this assessment service, the agency will comprehensively understand the current status of cryptography application in the relevant information systems and evaluate the gap between the current status and the corresponding levels stipulated in the Information Security Technology—Basic Requirements for Cryptographic Application of Information Systems (GB/T 39786-2021). This aims to achieve the goals of promoting construction, rectification, and application through assessment. On-site assessments and technical verifications will be conducted covering physical and environmental security, network and communication security, equipment and computing security, application and data security, key management, and security management. The agency will identify weak links and potential risk hazards in cryptographic applications, propose targeted rectification recommendations, and ensure the compliance, correctness, and effectiveness of cryptographic applications. Furthermore, cryptographic security protection measures will be precisely implemented to guarantee the authenticity, confidentiality, integrity, and non-repudiation of the information systems. (III) Service Period The service period for this project shall commence from the date of contract signing and continue until the project closing date (March 31, 2029). The specific service timeline will be implemented in phases based on the system launch schedule of the four informatization projects. (IV) Deliverables The deliverables required for this project are as follows: No. Report Submission Date/Phase

1 Mobilization Report Within 10 working days after contract signing and system launch (subject to the actual system launch date).

2 Information System Rectification List Within 10 working days after the completion of the gap assessment.

3 Cybersecurity Level Protection Assessment Report For Level 3 systems: Within 15 working days after the acceptance assessment is conducted upon the user's completion of rectification to meet the acceptance requirements. For the annual re-assessment report: The annual re-assessment must be initiated 3 months before the expiration of the previous year's assessment report, and the annual assessment report must be issued before the expiration of the previous year's report. For Level 2 systems: Within 15 working days after the acceptance assessment is conducted upon the user's completion of rectification to meet the acceptance requirements.

4 Filing Materials and Filing Receipt Issued within 10 working days after the assessment report is stamped by both parties and submitted online to the cyber police department.

5 Commercial Cryptography Application Rectification List Within 10 working days after the completion of the gap assessment.

6 Commercial Cryptography Application Security Assessment Report

For Level 3 systems: Within 15 working days after the acceptance assessment is conducted upon the user's completion of rectification

Context for bidders

We hold 3 notices from China International Tendering Co., Ltd., going back to September 20263 of them still open. There are 240 open IT & Telecom tenders in China. This one closes in 18 days.

Before you bid on this tender

A quick checklist to help you decide whether to bid and prepare a compliant submission for this it & telecom opportunity. Always verify the details on the official source.

  • Confirm the exact closing date and time (and time zone) on the official portal — deadlines are strict and can be revised by a corrigendum.
  • Read the full notice and every attached document, including the scope, specifications and any bill of quantities or terms of reference.
  • Check the eligibility criteria — prior similar experience, annual turnover, certifications and registrations — and make sure you qualify before investing effort.
  • Prepare any earnest-money deposit (EMD) or bid security and the required formats early; missing or wrongly-formatted documents are a common cause of rejection.
  • Note how bids must be submitted (online or physical), in what format, and whether a digital signature or portal registration is required.
  • Watch for corrigenda and clarifications right up to the deadline — requirements and dates can change.

More IT & Telecom tenders

All IT & Telecom tenders →

FreeTender mirrors this notice for reference. Verify the details and bid on the official portal.

Verify & apply on the official portal →