Tender detail
External penetration and security testing of the Lesser Poland Medical Information System platform
Summary
The tender concerns a 90-day service for comprehensive external grey-box penetration and security testing of the Lesser Poland Medical Information System platform (MSIM). The work covers authentication, authorization and access control, application and API vulnerabilities, cryptography and data protection, configuration, resilience and availability, monitoring and logging, security and privacy compliance, and the external attack surface. The contractor must prepare Rules of Engagement and a test plan, perform the agreed tests, report critical vulnerabilities within 4 hours, deliver a final report with evidence, CVSS v4.0 ratings and remediation recommendations, present the results, provide supporting documentation on request, and remove test traces. The bid must be submitted electronically in Polish by 7 September 2026 at 11:00 and the service must be completed within 90 calendar days of contract signature. Evaluation consists of gross price (60%), lead tester qualifications (30%) and the number of software testers assigned (10%). No bid guarantee is required; the successful bidder must provide performance security equal to 3% of the gross bid price before signing the contract.
More tender information after sign-in
The public view shows key tender details. Sign in to open official links, documents and AI tender support.