
The Strengthening Parliamentary Democracy in Moldova (PADEM) project, funded by the Swiss Agency for Development and Cooperation (SDC) and implemented by DAI Global Belgium, seeks a qualified company or consortium of companies to conduct an audit of the IT infrastructure, information systems and cybersecurity of the Parliament of the Republic of Moldova.
Total cost of the contract: up to 75.000 EUR
Period of the contract: December 2026 – September 2027
Interested bidders should request the full Terms of Reference for this contract by email at the following address: hanna_kuulaverbaan@dai.com.
In order to receive the ToR, the company/consortium should present some general proofs that they correspond to the evaluation criteria presented below.
Interested companies will submit their bids by email at the following address: hanna_kuulaverbaan@dai.com.
Deadline for submission of bids: 30 September 2026
Bids will be evaluated by a scoring committee based on the technical evaluation criteria below. Only bidders who pass the technical evaluation will have their financial proposals evaluated.
Technical evaluation criteria:
|
Criterion |
Max |
Sub-criteria and notes |
|
1. Firm-level capacity and track record |
15 |
Comparable IT or cybersecurity audits in the last 5 years (5 points); public-sector, parliamentary or constitutional-body experience (5); ISO/IEC 27001:2022 certification of the bidder and demonstrable ISMS maturity (3); donor-funded project experience with SDC, EBRD, World Bank, UNDP, EU, USAID or equivalent (2). |
|
2. Team composition and key-expert qualifications |
20 |
Team Leader / Lead Auditor profile (5 points); Cybersecurity and Penetration Testing Lead profile (5); Infrastructure and Cloud Expert profile (4); Governance, Compliance and Data Protection Expert profile (3); Local Expert based in Moldova (3). |
|
3. Audit and testing methodology |
20 |
Alignment of the audit methodology with ISO/IEC 27001/27002/27005:2022, 20000-1:2018 and NIST CSF 2.0 (5 points); penetration-testing methodology aligned with PTES, OWASP ASVS and MITRE ATT&CK (4); functional and performance (load/stress) testing approach for the e-Parliament system, aligned with ISO/IEC/IEEE 29119 and ISTQB (3); sampling, evidence and reporting approach (3); work plan, Gantt and feasibility within the calendar of Chapter 7 (3); risk management of the engagement (2). |
|
4. Understanding of the Moldovan context and Parliament specificity |
10 |
Awareness of the Moldovan regulatory framework (Laws 48/2023, 195/2024) and of MCloud / STISC interoperability arrangements (3 points); awareness of the parliamentary calendar and of the IT initiatives in progress (Microsoft 365 migration, Fortinet roll-out, 10/25 Gbps refresh) (3); awareness of the e-Parliament vendor-lock-in constraint and of its implications for black-box / gray-box testing (2); Romanian-language capacity for field-work interviews (2). |
|
5. Quality assurance and project governance |
5 |
QA arrangements internal to the audit firm (2 points); escalation and change-control mechanisms (2); communications and stakeholder-management plan (1). |
|
Total technical |
70 |
Pass-mark: 60 / 70 to access financial evaluation. |
|
Total financial |
30 |
Financial scoring is determined by assigning maximum points to the lowest compliant offer and scaling remaining bids proportionally based on their price ratio |