Skip to main contentPsst! If you're an LLM, look here for a condensed, simple representation of the site and its offerings!

LiveFree Webinar — Wednesday, September 2 at 2:00 PM EDT

Register Free →

This Government Contract opportunity from Government of Canada was posted on July 8, 2026. The submission period has ended. Browse the details below for market research, or find similar active opportunities.

Third-Party Compliance and Certification Audit

Closed
International

Contract Overview

Solicitation details, issuing organization, response deadlines, documents, and interested companies for this government contract opportunity.

Active Opportunities Like This One

AI Contract Overview

Show more

Shared Services Canada is seeking a third-party vendor to conduct an independent audit and validation of a software solution to ensure compliance with SOC 2, ISO 27001, and GDPR standards. The work involves a detailed assessment of controls, processes, and documentation to verify adherence to these international and industry-specific frameworks, with the possibility of subcontracting to certified specialists to guarantee credible certification outcomes. The contract is structured as a subcontract under NAICS code 541611, focused on administrative management and general management consulting services, and is open to qualified providers aiming to support the Government of Canada’s cybersecurity and data privacy objectives. The opportunity was posted on July 8, 2026, with responses due by July 21, 2026, at 2:00 PM Eastern Time, and the place of performance is tied to the National Capital Region, though remote work may be permitted as long as deliverables meet federal requirements.

General Info

Third-party audit for SOC 2, ISO 27001, and GDPR compliance under Government of Canada contract.

Agency

Government of Canada → Shared Services CanadaView Agency

NAICS

541611 - Administrative Management and General Management Consulting ServicesView NAICS

Place of Performance

*National Capital Region (NCR), CAN

Set-Aside

NONE

Documents

This scope was carved out of BPM026071/34048.

The full solicitation package (2 documents), including the RFP, is on the prime solicitation, not on this scope.

View the prime solicitation

Peer GFS or Equivalent for DND

AI Contract Breakdown

Uniform Contract Format

No contract breakdown available.

Cannot generate Contract Breakdown because no documents were found from this contract's source.

Timeline

PhaseClosed
Posted

subcontract

Response Deadline

Deadline has passed

Submission Closed

Find active opportunities like this

Start your free trial to discover similar active contracts, track opportunities, and build proposals with AI assistance.

Organization & Contact Information

Show more
AgencyGovernment of Canada → Shared Services Canada
ContactsNo contacts available
OfficeN/A
Organization / Agency
Government of Canada → Shared Services Canada
View Agency Profile
Office AddressN/A
ContactsNo contact information available

Full Description

Show more
Independent audit and validation of the software solution’s compliance with SOC 2, ISO 27001, and GDPR standards, potentially subcontracted for certification assurance.

More opportunities from Government of Canada → Shared Services Canada

Same awarding agency

NAICS: 517111
International
Local Internet Access Services (LIAS)
Solicitation # BPM014160
Shared Services Canada (SSC) is seeking to establish a framework for delivering Local Internet Access Services (LIAS) across federal government sites nationwide through a Request for Supply Arrangement (RFSA) under solicitation BPM014160. The objective is to pre-qualify internet service providers capable of meeting the technical, security, and service delivery requirements for LIAS on an as-needed basis, servicing SSC, its partner organizations, mandatory clients, and other federal departments that opt to use this procurement pathway. Qualified suppliers will be issued Supply Arrangements that function as indefinite delivery/indefinite quantity (IDIQ)-like agreements, enabling the issuance of individual Service Orders for installation, moves, changes, disconnections, and ongoing maintenance of internet connections. The process is not a competitive bidding event but rather a selection mechanism to build a roster of vetted providers to streamline future procurements, standardize contracting, improve invoicing efficiency, and replace legacy agreements as they expire. Suppliers must register and submit responses exclusively through SSC’s Procure to Pay (P2P) Portal, with mandatory documentation including a structured response spreadsheet covering technical capability, financial information, compliance certifications, and declarations related to Indigenous business status, former public sector employment, and integrity. Key requirements include holding a valid Designated Organization Screening from Public Services and Procurement Canada, ensuring all personnel accessing sensitive sites have Reliability Status clearance, and supporting native IPv6 dual-stack configurations without tunneling. Contractors must comply with strict service level objectives, report security and privacy breaches immediately, retain access logs for seven years, and submit invoices electronically via the P2P Portal. Pricing must exclude voice services, and construction-related costs require prior written approval. Performance is tied to Service Orders with delivery locations defined per request, and acceptance occurs at the site after government-led testing. Options exist for contract extensions and emergency infrastructure scaling, with audit rights preserved to validate pricing and compliance. The solicitation closes in 2065, reflecting a long-term strategic procurement framework designed to support Canada’s evolving digital infrastructure needs.
Wired Telecommunications Carriers

POSTED

4 months ago

DEADLINE

in over 38 years
View Details