Request for Proposal (RFP) - CTY Greece Information System (CIS)
1. Introduction
The Center for Talented Youth (CTY) Greece, a division of Anatolia College and an affiliate of the Johns Hopkins Center for Talented Youth, invites qualified software vendors to submit detailed information about potential solutions to replace and/or enhance the CTY Information System (CIS).
The current CIS supports CTY’s end-to-end academic and administrative workflows, including user management, exam scheduling, program operations, student records, scholarship processing, and financial transactions.
The current CTY Information System (CIS) integrates multiple functional areas that collectively support over 13000 students, 90 instructors, and 20 annual program sessions.
As CTY’s operations have expanded in complexity and scale, the institution seeks to modernize its digital infrastructure to deliver:
- Greater operational efficiency
- Seamless user experience for staff, instructors, students, and parents,
- Enhanced data security and GDPR compliance, and
- Integrated analytics and decision-support capabilities.
This Request for Proposal (RFP) is issued and follows the previous RFI, with the aim of obtaining detailed and comprehensive information regarding available solutions, technologies, methodologies, and implementation approaches relevant to the project scope. The purpose of this RFP is to evaluate potential vendors’ capabilities and proposed approaches. Issuance of this RFP does not constitute a commitment to award a contract or to procure any products or services. The information provided in the responses will be used to support evaluation, decision-making, and potential next steps in the procurement process.
2. System Overview Requirements
The CIS should be:
- Web-based with secure access from modern browsers
- Role-based, supporting multiple user types (parents, instructors, finance, medical staff, academic admins)
- Integrated with LDAP for staff authentication
- Database-backed for storing student, exam, financial, and medical data
- Integrated with Moodle through API endpoints (Web Services)
- Secure (data integrity, security, and GDPR compliance)
- Auditable, with logging of all administrative actions
3. User Roles & Functional Requirements
The system supports multiple user roles—such as Administrator, Instructor, Teaching Assistant, Registrar, and Finance Officer—using role-based access control (RBAC) so each user only accesses what they need. It includes multi-factor authentication (MFA) and single sign-on (SSO) for secure login, and keeps audit trails of all user activity.
3.1 Parents
- Register students and view academic/exam results
- Select and pay for exams and programs
- Receive automated email/SMS notifications
- Access to student progress reports
3.2 Instructors
- View student profiles and academic history
- Manage courses and Moodle groups
- Upload teaching materials and track grades
- View exam results and percentiles
3.3 Cashier / Finance Staff
- Manage orders, payments, and receipts
- Apply for scholarships and CTY Fund waivers
- Generate financial reports and VAT documentation
- Audit trail for all financial transactions
3.4 Medical Staff
- Access and update student medical records
- Record allergies, medications, and incidents
- Audit logs for all changes
- Integration with alerts for instructors if necessary
3.5 Moodle & Course Administrator
- Assign course templates and student groups
- Propagate courses and track failed transfers
- Remove LDAP flags from completed accounts
3.6 Academic Administrator
- Full access to students, exams, programs, and financials
- Approve scholarships, exam exceptions, and promotions
- Generate system-wide reports and analytics
4. Exams Management
The system must support:
- Exam creation, categorization, and scheduling (online and in-person)
- Candidate registration and slot allocation
- Exam venue and seat management
- Integration with testing and scoring platforms
- Scoring algorithms and grade normalization
- Result review, approval, and release workflows
- Automated generation of eligibility letters or emails
- Statistical reporting (performance distributions, item analysis)
5. Programs & Courses
Requirements include:
- Support for all types of programs (First come-first served / Interest Form Programs and Invitation-Only Programs, Weekend, Online, Summer, Teasers)
- Course linking and student group management
- Automated or manual Moodle propagation
- Tracking enrollment, attendance, and student progress
- Managing program-specific scholarships
- Capacity management and automated enrollment checks
6. Scholarships & Financials
Scholarships
- Scholarship program setup & criteria definition (financial need, grades, exam results)
- Automated eligibility calculation based on student performance and demographics
- Integration with student profiles for scholarship linkage
- Approval workflows (committee review, audit trail)
- Financial aid tracking and disbursement reconciliation
- Reporting on scholarship utilization and demographics
Financials
- Creation of orders, line items, and payment tracking
- Automatic application of scholarships or CTY Fund waivers
- Receipt generation and cancellation with an audit trail
- Monthly/annual reporting capability
- Integration with external financial systems, if required
- Payment tracking and reconciliation
- Refund management
- Financial dashboards for revenue, collections, and outstanding balances
- Multi-currency and multi-tax support
7. Students Management
- Full student profile management with academic, financial, and medical information
- Academic history, grades, progress reports, and promotions
- Medical forms, incidents, and alerts
- Integration with financial and program modules
- Duplicate detection and profile merging
- Student lifecycle tracking (application → admission → enrollment → completion)
- Digital document management (certificates, transcripts, consent forms)
- Multilingual interface support (English/Greek)
8. Administration & Reporting
The CIS should provide:
- Centralized reporting engine
- Custom and ad-hoc report creation with filters and export options
- Performance dashboards (student success, enrollment, scholarship use)
- Administrative reports (user activity, exam results, financial summaries)
- Data visualization tools (charts, trend analysis, drill-down capability)
- Role-based access to reports and dashboards
- Automated notifications (email/SMS) for exams, programs, and payments
- Mass communication tools for parents, students, and staff
- Logging and audit trails for all administrative actions
- Exception handling dashboards for duplicates, failed payments, missing grades, and system errors
- Multilingual interface support (English/Greek)
9. Security & Compliance
The system must ensure:
- Minimum 12-character password policy with complexity requirements
- Two-factor authentication for administrators
- Session timeout after 30 minutes of inactivity
- Encryption of sensitive data at rest and in transit
- Audit logs and user activity tracking
10. Integration Requirements
- Moodle: Full course and group propagation, grade syncing
- LDAP: Staff authentication and user role management
- Email/SMS Systems: Automated notifications for events, payments, and alerts
- Financial Systems: Optional integration for bank or accounting reconciliation
11. Vendor Response Guidelines
Vendors responding to this RFP should provide:
- Overview of the proposed CIS solution
- Compliance with the listed functional requirements
- Security and data privacy measures
- Architecture and scalability approach
- Integration capabilities with Moodle, LDAP, and financial systems
- User management, roles, and workflow support
- Reporting and analytics features
- Implementation timeline and support model
- Licensing and pricing model
- References and case studies
12. Server and Hosting Specification
The solution must be hosted on infrastructure optimized for the specific platform within the European Union.
- Deployment Model: Managed Cloud (SaaS) or On-Premises with strict environment isolation (Development, Staging, Production).
- Infrastructure Security: Server-level Web Application Firewall (WAF) and DDoS protection.
- Patch Management: Mandatory application of critical security patches (OS and CMS Core) within 48 hours; routine updates tested in Staging first.
- Backup Policy: Automated daily database and file backups, stored offsite, with a minimum 30-day retention period (ISO 27001 Control 8.13).
- Disaster Recovery:
- Recovery Point Objective (RPO): < 1 hour (Maximum data loss).
- Recovery Time Objective (RTO): Next Business Day / < 24 hours (Acceptable downtime).
- Performance: Server-side caching (Redis/Varnish) and CDN integration.
- Data Sovereignty: Hosting provider must be ISO 27001 certified and GDPR compliant.
13. RFP Submission
- New Deadline: [20/2/2026]
- Contact: [Vasileios Karkampounas (Αυτή η διεύθυνση ηλεκτρονικού ταχυδρομείου προστατεύεται από τους αυτοματισμούς αποστολέων ανεπιθύμητων μηνυμάτων. Χρειάζεται να ενεργοποιήσετε τη JavaScript για να μπορέσετε να τη δείτε.)]
- Submission Format: PDF or Word document
Questions: Submit in writing to the contact above by [2/2/2026]
