Opportunity

CanadaBuys #RFx004510

CMHC Solicitation for Cyber Security Governance, Risk, and Compliance SaaS Solution and Services

Posted

August 21, 2026

Respond By

September 21, 2026

Identifier

RFx004510

NAICS

541512, 541513

CMHC, a Crown Corporation under the Government of Canada, is seeking a cloud-based Cyber Security Governance, Risk, and Compliance (GRC) SaaS solution to enhance operational efficiency and cyber risk visibility. - Government Buyer: - Canada Mortgage and Housing Corporation (CMHC) - Cyber Security team, Procurement Office - Contracting authority: Christine Brown - OEMs and Vendors: - No specific OEMs or vendors are named; open to qualified suppliers - Products/Services Requested: - Cyber Security GRC SaaS solution - Features: role-based access control, workflow automation, integration with SIEM/IAM/CMDB, customizable governance framework, cyber risk management, regulatory compliance, risk modeling, reporting, scalability, and AI governance - All CMHC data must be stored and processed exclusively in Canada - Implementation and configuration services - Includes integration, technical support, consultation, training, customization, testing, data migration, and ongoing maintenance - Unique/Notable Requirements: - Mandatory SaaS hosting and Canadian data residency - Compliance with security standards (NIST, ISO, CIS, MITRE) - Personnel security clearances required - Strict eligibility: Canadian suppliers and CETA trading partners only - Anti-lobbying and conflict of interest provisions - Pricing must include software subscription, implementation, training, and ongoing support - Contract Details: - Non-exclusive agreement - Five-year base period with two optional renewal years (up to seven years) - Competitive open bidding; selection based on technical merit and price

Description

Canada Mortgage and Housing Corporation (CMHC) is seeking proposals from qualified proponents for the provision of a Cyber Security Governance, Risk, and Compliance (GRC) solution. The solution aims to support operational efficiency, regulatory alignment, and cyber risk visibility across IT and Cyber domains. The contract is intended to be non-exclusive, with a duration of five years plus two optional renewal years, totaling seven years. The procurement method is competitive open bidding, and the selection criteria is the highest combined rating of technical merit and price.

View original listing