2026-0119 Consultancy Support for CIS Security (NS) - THU 20 Aug
EMW, Inc.
| Company | EMW, Inc. |
| Category | Security |
| Location | Brussels |
| Remote | Hybrid |
| Employment | Contract |
| Level | Not stated |
| Salary | Not stated by the employer |
| Posted | 11 Aug 2026 |
| Last verified | 12 Aug 2026 |
| Source | Employer ATS (workable) |
Description
BIDDING INSTRUCTIONS 1. Technical Proposal In submitting their bids, Bidders shall provide a proposal clearly providing the following information: a) Proposed approach to address the required scope of work. Minimum Requirements: The proposal shall include: A clear description of the approach to deliver the full Scope of Work, covering the required GWSW support activities, including: refinement of the NCIA CIS Security Governance Process; alignment with NCIA policies, notices and directives; gap analysis of CIS security roles and responsibilities; update of RACI matrix and development/refinement of Terms of Reference; support to internal and external communication plans. A defined delivery methodology (e.g. iterative / Agile approach) aligned with the SOW. A milestone plan consistent with the required timeline (2 months). Clear linkage between: refinement of the NCIA CIS Security Governance Process; alignment with NCIA policies, notices and directives; gap analysis of CIS security roles and responsibilities; update of RACI matrix and development/refinement of Terms of Reference; support to internal and external communication plans. Non-Compliance Conditions The proposal shall be deemed non-compliant if: The proposed approach is missing or incomplete. The proposed approach does not cover all phases of the SOW. The proposed milestone plan is absent or inconsistent with the required delivery structure. b) Experience of assigned resources. Minimum Requirements: The proposal shall demonstrate that the assigned resources collectively have relevant and proven experience directly aligned with the scope of this SOW, including: Governance processes in the context of CIS Security. Development, refinement, or assessment of security governance roles and responsibilities, including: RACI matrices; Terms of Reference; stakeholder accountability models; governance decision making structures. Gap analysis in relation to security governance, including: assessment of existing roles and responsibilities; identification of overlaps, gaps and accountability issues; development of practical recommendations for improvement. Development of large and complex communication strategies and communication plans, including: internal stakeholder communication; external stakeholder communication; communication of governance changes; support of organizational change and stakeholder engagement. Experience with CIS systems, including military and/or civilian CIS environments. Experience with CIS-related international, commercial, or industrial standards. Experience in Service Design and Management. Knowledge and experience of NATO and/or NCIA environments. Preparation of governance documentation, reports, recommendations, and implementation guidance suitable for stakeholder use, including: governance process description; reports and recommendations; RACI matrices; Terms of Reference; GAP analyses; implementation roadmap or action plan; communication plans. Possession of NATO SECRET security clearance. Non-Compliance Conditions The proposal shall be deemed non-compliant if: The proposed team does not demonstrate direct experience in the following areas: CIS security governance; development or refinement of roles and responsibilities, RACI matrices and Terms of Reference; development of communication strategies and communication plans; gap analysis of governance roles, responsibilities and stakeholder accountability. Experience is generic, for example limited to general IT governance, standard project management, or advisory work, and is not aligned with the specific scope of this SOW. Proposed resources do not meet the minimum seniority expectations or lack relevant experience for their assigned roles. The proposal does not demonstrate practical implementation experience (i.e., only advisory or conceptual experience is provided) in delivering governance-related outputs, including RACI matrices, Terms of Referen