Provision of Static Application Security Testing (SAST) and Dynamic Application Security Testing (DAST) Tool
KenTrade seeks a vendor to supply, install and support an integrated SAST and DAST application security testing platform. Tender security KSh 120,000. Closes 22 April 2026 at 10:00 EAT.
Submit Proposal
Opens on the procurement portal
Official Title
Tender No. KTNA/OT/06/2025/2026 - Provision of SAST and DAST Tool
Overview
The Kenya Trade Network Agency (KenTrade), the state agency operating the Kenya National Electronic Single Window System (KenTradeNet) under the National Treasury, has issued an open national tender for the supply, delivery, installation, configuration and ongoing support of an integrated Static Application Security Testing (SAST) and Dynamic Application Security Testing (DAST) toolset. The platform will be used by KenTrade application security and DevSecOps teams to scan source code, container images and running web applications across the Single Window environment, which handles trade documentation for thousands of importers, exporters, customs agents and government partners across Kenya. Bidders should expect to integrate with KenTrade existing CI/CD pipelines and security operations workflows. Prices must be expressed in Kenya Shillings, inclusive of all taxes and delivery costs, and remain valid for 175 days from the date of tender opening. Electronic submissions are NOT permitted, and tenders will be opened publicly at the KenTrade Boardroom (1st floor, Embankment Plaza, Upper Hill, Nairobi) immediately after the deadline.
Scope of Work
Supply, delivery, installation and commissioning of a SAST tool covering at minimum the languages used in KenTrade application stack. Supply, delivery, installation and commissioning of a DAST tool capable of scanning authenticated and unauthenticated web applications and APIs. Integration with KenTrade source code repositories and CI/CD pipelines. User training and knowledge transfer to KenTrade ICT and security teams. Provision of technical support, maintenance and software updates for the contract duration. Documentation of installation, configuration and standard operating procedures.
Requirements & Qualifications
Bidders must be legally registered firms able to invoice in Kenya. Tender security of KSh 120,000 (approximately USD 925) is mandatory, valid for 150 days from tender closing, in the form of a bank guarantee or guarantee from a PPRA-listed insurance company. All pages and attachments must be chronologically serialised. Bidders must register with KenTrade by emailing [email protected] with full company details (name, postal, physical, email, telephone) before submission. Prior experience supplying SAST/DAST tools to government, financial services or trade-facilitation environments is expected.
Evaluation Criteria
Mandatory compliance check (tender security, registration, serialisation, completeness). Technical evaluation against the specifications in the tender document including coverage of programming languages, scan accuracy, integration capabilities, support model and vendor track record. Financial evaluation of total cost of ownership over the contract period. Award to the lowest evaluated responsive bidder.
Contact
NameKenTrade Procurement Office
Email[email protected]
Kenya