Lista wymaganych dokumentów/oświadczeń
Do wypełnionego i podpisanego przez Wykonawcę formularza ofertowego – stanowiącego załącznik nr 2 należy dołączyć:
a) oświadczenie o braku powiązań osobowych lub kapitałowych; Oświadczenie to, jak i pozostałe, winno zostać podpisane przez osobę/y uprawnioną/e do reprezentowania Wykonawcy składającego ofertę,
b) oświadczenie o niepodleganiu sankcjom,
c) oświadczenie Wykonawcy wskazujące podmioty, które przeprowadzą poszczególne audyty wraz z załączeniem kopii aktualnego certyfikatu akredytacji jednostki certyfikującej ISO oraz dokumentu potwierdzającego status licencjonowanej firmy CPA/AICPA,
d) referencje,
e) opis techniczno-funkcjonalny oferowanej platformy GRC potwierdzający spełnienie kryteriów integracyjnych i automatyzacji.
Szczegółowy opis w załączniku Zapytanie ofertowe SMART_1_08_2026.
The following must be attached to the bid form—constituting Attachment No. 2—completed and signed by the Contractor:
a) a declaration of no personal or capital ties; This declaration, as well as the others, must be signed by the person(s) authorized to represent
the Contractor submitting the bid,
b) a statement confirming that the Contractor is not subject to sanctions,
c) a statement regarding the GDPR,
d) a statement by the Contractor identifying the entities that will conduct the individual audits, along with a copy of the current accreditation certificate of the ISO certification body and a document confirming the status of a licensed CPA/AICPA firm,
e) references,
f) a technical and functional description of the proposed GRC platform confirming compliance with integration and automation criteria.
A detailed description of the terms is provided in the attachment “Request for Proposals
SMART_1_08_2026”.
Dodatkowe warunki udziału
W celu uniknięcia konfliktu interesów zamówienie nie może być udzielone podmiotom powiązanym osobowo lub kapitałowo z Zamawiającym.
Konflikt interesów oznacza każdą sytuację, w której osoby biorące udział w przygotowaniu lub prowadzeniu postępowania o udzielenie zamówienia lub mogące wpłynąć na wynik tego postępowania mają, bezpośrednio lub pośrednio, interes finansowy, ekonomiczny lub inny interes osobisty, który postrzegać można jako zagrażający ich bezstronności i niezależności w związku z postępowaniem o udzielenie zamówienia.
Przez powiązania kapitałowe lub osobowe rozumie się wzajemne powiązania między Zamawiającym lub osobami upoważnionymi do zaciągania zobowiązań w imieniu Zamawiającego lub osobami wykonującymi w imieniu Zamawiającego czynności związane z przygotowaniem i przeprowadzeniem procedury wyboru wykonawcy a wykonawcą, polegające w szczególności na:
a) uczestniczeniu w spółce jako wspólnik spółki cywilnej lub spółki osobowej, posiadaniu co najmniej 10% udziałów lub akcji (o ile niższy próg nie wynika z przepisów prawa), pełnieniu funkcji członka organu nadzorczego lub zarządzającego, prokurenta, pełnomocnika,
b) pozostawaniu w związku małżeńskim, w stosunku pokrewieństwa lub powinowactwa w linii prostej, pokrewieństwa lub powinowactwa w linii bocznej do drugiego stopnia, lub związaniu z tytułu przysposobienia, opieki lub kurateli albo pozostawaniu we wspólnym pożyciu z wykonawcą, jego zastępcą prawnym lub członkami organów zarządzających lub organów nadzorczych wykonawców ubiegających się o udzielenie zamówienia,
c) pozostawaniu z wykonawcą w takim stosunku prawnym lub faktycznym, że istnieje uzasadniona wątpliwość co do ich bezstronności lub niezależności w związku z postępowaniem o udzielenie zamówienia.
Wykonawca zobowiązany jest dołączyć do oferty oświadczenie o braku ww. powiązań według wzoru załączonego do niniejszego zapytania ofertowego.
To avoid a conflict of interest, the contract may not be awarded to entities personally or financially affiliated with the Contracting Authority.
A conflict of interest means any situation in which persons involved in the preparation or conduct of the procurement procedure, or who may influence the outcome of such a procedure, have, directly or indirectly, a financial, economic, or other personal interest that could be perceived as compromising their impartiality and independence in connection with the procurement procedure.
Capital or personal ties are understood to mean mutual ties between the Contracting Authority or persons authorized to incur obligations on behalf of the Contracting Authority, or persons performing activities on behalf of the Contracting Authority related to the preparation and conduct of the contractor selection procedure, and the contractor, consisting in particular of:
a) participation in a company as a partner in a general partnership or a partnership, holding at least 10% of the shares or stock (unless a lower threshold is provided for by law), serving as a member a supervisory or management body, a proxy, or an authorized representative,
b) being married to, related by blood or marriage in a direct line, related by blood or marriage in a collateral line up to the second degree, or related by adoption, guardianship or conservatorship, or cohabiting with the contractor, its legal representative, or members of the management or supervisory bodies of contractors bidding for the contract,
c) or having a legal or factual relationship with the contractor such that there is reasonable doubt as to their impartiality or independence in connection with the procurement procedure.
The contractor is required to attach to the bid a statement confirming the absence of the aforementioned ties, using the template attached to this request for proposals.
Uprawnienia do wykonywania określonej działalności lub czynności
Akredytacje i uprawnienia audytorskie. Podmiot bezpośrednio przeprowadzający dany audyt (Wykonawca lub jego wskazany podwykonawca) musi posiadać następujące uprawnienia:
Dla obszaru ISO 27001: Ważna akredytacja wydana przez Polskie Centrum Akredytacji (PCA) lub równoważną zagraniczną jednostkę certyfikującą. Dla obszaru SOC 2: Status licencjonowanej firmy audytorskiej CPA (Certified Public Accountant) zrzeszonej w AICPA (American Institute of Certified Public Accountants).
Dokumenty na potwierdzenie: Oświadczenie Wykonawcy wskazujące podmioty, które przeprowadzą poszczególne audyty wraz z załączeniem kopii aktualnego certyfikatu akredytacji jednostki certyfikującej ISO oraz dokumentu potwierdzającego status licencjonowanej firmy CPA/AICPA.
Accreditations and audit qualifications. The entity directly conducting the audit (the Contractor or its designated subcontractor) must possess the following qualifications: For the ISO 27001 scope: A valid accreditation issued by the Polish Center for Accreditation (PCA) or an equivalent foreign certification body. For the SOC 2 scope: Status as a licensed CPA (Certified Public Accountant) audit firm affiliated with the AICPA (American Institute of Certified Public Accountants).
Supporting documents: A statement from the Contractor listing the entities that will conduct the individual audits, accompanied by copies of the ISO certification body’s current accreditation certificate and a document confirming the status of a licensed CPA/AICPA firm.
Wiedza i doświadczenie
Doświadczenie Wykonawcy Wykonawca (lub podmiot wyznaczony do realizacji doradztwa i audytów) musi wykazać się doświadczeniem w wdrażaniu i audytowaniu standardów ISO 27001, SOC 2 oraz GDPR w organizacjach działających w modelu SaaS.
Dokumenty na potwierdzenie: Przedstawienie referencji lub dowodów należytego wykonania usług pochodzących od co najmniej 3 różnych klientów (będących dostawcami oprogramowania w modelu SaaS), u których Wykonawca pomyślnie zrealizował projekty wdrożeniowe lub audytowe w zakresie ISO 27001, SOC 2 lub GDPR w ciągu ostatnich 3 lat. (Pełna lista zrealizowanych usług nie jest wymagana w celu ochrony poufności danych handlowych).
Contractor’s Experience The Contractor (or the entity designated to perform consulting and auditing services) must demonstrate experience in implementing and auditing ISO 27001, SOC 2, and GDPR standards in organizations operating under the SaaS model.
Supporting Documents: Submission of references or evidence of satisfactory service performance from at least 3 different clients (who are SaaS software providers) for whom the Contractor has successfully completed implementation or audit projects related to ISO 27001, SOC 2, or GDPR within the last 3 years. (A full list of services provided is not required to protect the confidentiality of commercial data.)
Potencjał techniczny
Wymagania techniczne wobec systemu informatycznego (GRC) Oferowana w ramach zamówienia platforma GRC musi umożliwiać integrację z infrastrukturą chmurową (np. Azure, AWS) za pomocą API, automatycznie pobierać dowody audytowe (evidence collection) oraz posiadać prekonfigurowane mapowanie mechanizmów kontrolnych pod standardy ISO 27001, SOC 2 oraz GDPR.
Dokumenty na potwierdzenie: Opis techniczno-funkcjonalny oferowanej platformy GRC potwierdzający spełnienie kryteriów integracyjnych i automatyzacji.
Technical Requirements for the IT System (GRC) The GRC platform offered under this contract must support integration with cloud infrastructure (e.g., Azure, AWS) via API, automatically collect audit evidence, and include preconfigured mappings of control mechanisms to the ISO 27001, SOC 2, and GDPR standards.
Supporting documents: A technical and functional description of the proposed GRC platform confirming compliance with the integration and automation criteria.