We are a logistics and fleet software company in Riyadh with 14 employees. Last week, we bid on a vendor tender for a semi-public energy distribution firm. The technical specifications asked for compliance certification or a formal commitment to the local cybersecurity authority's essential controls and vendor security requirements.
We've taken on smaller projects in Turkey and the Gulf before, but this is our first time running into such a strict, formal cybersecurity compliance clause. We don't have a full-time cybersecurity specialist; we handle IT with an external freelance engineer. Our annual budget is tight, and this contract is worth around 350,000 SAR.
Does the tender expect a full third-party audit report or just a self-assessment declaration? How much does it cost a small business to implement these controls from scratch, and what is the smartest way to navigate this without losing the bid?