South Africa’s Department of Public Service and Administration has opened a new bid, SCM003/2026, to build and deliver a training programme for Departmental Information Security Officers across the public service. The practical significance is larger than a typical training contract: the officers being targeted are the people assigned to turn government security policy into working controls for identity, endpoints, networks, applications, cloud services and suppliers.

ITWeb first highlighted the procurement in its weekly tender roundup. The underlying DPSA tender record confirms that proposals are due by 11:00 a.m. on 27 August 2026 and that the assignment covers both course development and delivery, rather than the purchase of an off-the-shelf security-awareness package.

There is also an important procurement detail missing from the roundup. DPSA’s tender register shows an earlier, identically titled DISO training procurement, SCM001/2026, closed on 29 July 2026. The new SCM003/2026 solicitation is now listed as open, but the department has not published an explanation for the rapid re-advertisement, an award for the earlier tender, or whether the earlier process was found non-responsive, cancelled before award, or replaced for another reason.

For security professionals, that distinction matters. A new tender number and a new deadline mean suppliers that considered the July opportunity closed should treat this as a live procurement, while departments waiting for a standardized programme should not assume training delivery has begun.

Officials monitor cybersecurity dashboards in a high-tech command center featuring South African symbols.The DISO role already carries operational security duties​

The DPSA’s 2022 Directive on Public Service Information Security requires every department head to designate an official to perform the Departmental Information Security Officer function. The DISO is accountable to the Government Information Technology Officer on information-security matters, while the departmental ICT steering committee must operate as an information-security forum.

This is not a ceremonial compliance appointment. The directive places concrete security obligations around the position’s remit, including maintaining an information security policy, identifying and recording ICT-related business risks, driving security awareness, and helping departments implement security controls across their systems and data.

The policy also requires departments to run continuing awareness programmes that teach employees to recognize and report attacks such as phishing, baiting and tailgating. It specifically calls for role-targeted skills training for system administrators, web application developers and helpdesk administrators. In other words, a DISO training programme will be expected to prepare participants to coordinate technical teams, rather than merely distribute annual security slides.

For Windows and enterprise administrators, the directive’s requirements overlap with routine operational work: monthly operating-system and application patching, vulnerability scanning and remediation, role-based access control, formal access reviews, secure remote access, incident reporting, supplier assurance and cloud-service due diligence. A department may own those technical tasks across infrastructure, service-desk, application and procurement teams, but the DISO is one of the roles expected to ensure that the controls form a coherent programme and can be evidenced.

DPSA is paying for a structured capability, not a single course​

According to the tender description detailed by ITWeb, the successful provider must develop and customize a learning pathway for current and prospective DISOs. The requested material spans governance and strategic alignment, information risk management, policy development and enforcement, regulatory compliance, awareness programmes, technical-control assurance, third-party oversight and the case for security resources.

The range is revealing. Government departments are being asked to establish an information-security capability that reaches beyond the classic perimeter-security model of firewalls, web filtering and endpoint protection. The specification includes network, application and cloud security, emerging trends, hands-on exercises and real-world case studies. That moves the desired role closer to an enterprise security manager or CISO function, even though a DISO’s authority and resources will vary by department.

The tender documents use an 80/20 preference-point system: 80 points for price and 20 for defined ownership-related procurement goals. They require a total, VAT-inclusive cost for all activities and outputs, but do not publish a ceiling value or a target date by which the course must be designed, accredited or delivered. They also do not state how many officers will be trained, how many departmental cohorts are expected, whether courses will be delivered in person or remotely, or how competency will be assessed after completion.

Those omissions leave the most consequential implementation questions unanswered. A course can explain identity governance, incident response and cloud-risk review; it cannot by itself give a DISO authority to require remediation, fund a modern endpoint stack, or compel a supplier to accept stronger contractual controls.

The tender follows a policy gap DPSA has already acknowledged​

DPSA’s 2026/27 Annual Performance Plan offers a useful clue to why the training contract is being pursued now. The department says a portion of its funding for computer services will support external resources to upskill government DISOs and improve information-security governance. It also ties the work to guidelines identified through a compliance report.

That language suggests the training programme is part of a remedial governance effort, not simply a professional-development perk. The public performance plan does not identify the departments with compliance weaknesses, quantify the gaps, or publish the underlying assessment. It does, however, show that DPSA has formally budgeted for external assistance aimed at the DISO function.

The difference between training and implementation will be the critical measure once a provider is appointed. A capable programme should leave officers with repeatable operating artifacts: risk-register templates, control-assurance methods, incident escalation paths, supplier questionnaires, access-review routines and metrics that senior departmental leadership can review. Without those, the state risks producing people who understand the directive but still lack a practical way to demonstrate compliance.

The directive itself is prescriptive enough to make that test concrete. Departments must account for secure system development, monthly patch management, at least biannual vulnerability scanning and remediation, access-control processes based on least privilege, and due diligence before choosing cloud service providers. These are controls that generate evidence. A credible DISO programme should teach participants how to request, validate and retain that evidence—not merely describe the controls at a high level.

A re-advertised tender adds delay to the security programme​

The most immediate finding from the procurement record is that SCM003/2026 follows the closed SCM001/2026 bid for the same training assignment. DPSA has not said that the July process was cancelled, but it also has not listed an award against it. The department should clarify whether the new tender is a formal restart and whether its scope, evaluation criteria or delivery timetable changed.

That matters to bidders as well as public-sector IT teams. Re-advertised procurement can reset the competition, extend evaluation and postpone the point at which departments receive the planned training. Meanwhile, the information-security directive remains in force: departments are still expected to maintain policies, designate DISOs, run awareness programmes, manage access and patch systems.

The 27 August deadline is therefore not the end of the story. It is the start of another procurement cycle for a programme DPSA had already sought once this year. Until the department publishes the outcome of SCM003/2026—and explains the disposition of SCM001/2026—the public record shows an acknowledged need to strengthen information-security governance, but no evidence that the nationwide DISO training programme is yet in delivery.