Security tender requirements in South Africa — the corporate procurement checklist (2026)

Corporate procurement teams in South Africa see dozens of security company tender responses a year, and most of them are wrong in the same ways: expired PSIRA certificates, no CSD number, no POPIA policy, public liability cover set too low, and SLAs written by the guard company instead of the client.
This checklist is written for procurement, legal and risk teams onboarding a security provider in 2026. Use it as an evaluation grid — pass/fail on the compliance pack before you even score the price.
1. Company-level compliance documents
PSIRA certificate — current, in the trading name of the company tendering, not a related entity. Verify the registration number on the PSIRA public register yourself. SAPS registration number for firearm-holding entities. CIPC company registration. CSD (Central Supplier Database) profile — active, current tax status verified, banking verified. Tax clearance certificate — issued in the last 12 months. VAT registration certificate (if applicable). BEE certificate — sworn affidavit for EMEs, verification certificate for QSEs and above.
Missing any of these is a fail. Do not compensate for it in the scoring.
2. Sector-specific levies and contributions
PSSPF (Private Security Sector Provident Fund) — proof of contribution on all deployed officers. NBCPSS (National Bargaining Council for the Private Security Sector) — proof of levies paid. UIF and SDL — proof of registration and current contribution. COIDA / Return of Earnings — Letter of Good Standing (LOGS) from the Compensation Fund, current for the tender period.
A serious provider has all four of these in one PDF, current-dated. If your tender responses show even one gap, the officers on your site may not be legally covered.
3. Officer-level compliance
For every officer to be deployed on your site: individual PSIRA registration and grading appropriate to the post. SAPS firearm competency and section-16 licence for every armed officer. Medical certification current (typically annual). Fingerprint clearance / criminal record check. Signed acknowledgement of your site's SOP.
Your tender should reserve the right to spot-audit any of these on any deployed officer at any time, without notice. Put it in the SLA.
4. Insurance cover levels
Specify minimums, not "adequate cover". For most corporate sites in 2026: public liability of at least R10m per event, R20m for high-risk or high-value sites. Professional indemnity of at least R5m. Asset-in-transit cover appropriate to any cash or valuables the officers will handle. Employers' liability confirmed via Letter of Good Standing.
Ask for the insurance schedule and the broker's contact. "Trust us, we're covered" is not an answer.
5. POPIA readiness
Every guarding operation processes personal information — visitor logs, CCTV recordings, staff and contractor screening, incident reports. Your provider must supply a POPIA policy, name their Information Officer, describe data retention and destruction periods, and confirm sub-processor arrangements (control room, CCTV monitoring, dispatch). Paper visitor books almost never comply.
Add a POPIA clause to your MSA that binds the provider to notify you of any personal-information breach within 24 hours.
6. SLA — written by you, not them
The single biggest procurement mistake is accepting the provider's boilerplate SLA. Write your own, and require: officer grading per post; hours of coverage per post; supervisor visit frequency; patrol frequency and route (with GPS proof); response time to alarms, panics and incidents; incident reporting deadline; monthly SLA report content and format; escalation matrix with named contacts and phone numbers; cure periods for breaches; and a termination-for-material-breach clause with a defined cure window.
Attach the SLA to the tender. Responses that reject or materially amend it get scored down. Responses that accept it as-is get scored up.
7. Reporting deliverables
Daily occurrence book (electronic, exportable). Weekly patrol / incident summary. Monthly SLA report (as specified above). Quarterly risk review meeting with the site owner. Ad-hoc after-action report on any material incident, delivered within 48 hours.
If your provider cannot show you a template of each of these before award, they will not produce them after award.
8. Pricing structure to require in the response
Per-post monthly rate with grading, armed / unarmed, hours and NBCPSS compliance stated. Escalation formula tied to the annual NBCPSS wage adjustment, not to CPI. Vehicle patrol and supervisor visit costs itemised. Any "admin", "call-out" or "after-hours" surcharges disclosed on the pricing schedule. Total contract value over the tender period, clearly stated.
Ambiguity in pricing at tender stage becomes disputed invoices at month three.
9. References — check them
Ask for three current corporate references of comparable scale, all reachable directly by the reference contact's business email and mobile. Call two of them. Ask specifically: response times, quality of monthly reporting, how disputes were handled, whether they'd re-appoint. Providers who supply personal Gmail references for corporate work are hiding something.
10. Red flags on tender responses
Expired PSIRA certificate. No CSD number. Missing POPIA policy. Public liability cover under R5m for a corporate site. SLA rewritten by the provider. Pricing that comes in materially below the working ranges in our
cost of hiring security guards guide. Any of these on their own is a reason to disqualify — not to negotiate.
Warhawk tender pack
Warhawk keeps the full corporate tender pack current — PSIRA, SAPS, CIPC, CSD, tax clearance, BEE, PSSPF, NBCPSS levies, LOGS, POPIA policy and insurance schedule — all in one PDF, ready to send the same day. Email admin@warhawk.co.za with your RFP.
