Skip to content
TenderMatch
The recorded submission deadline has passed. Find open opportunities. Check the official notice for amendments.
← Tenders / Managed Firewall Service, Security Operation Centre (SOC), Security Incident and Event Management (SIEM) and Incident Response Managed Service for Mercy University Hospital
Closed IT & Software Services SME Suitable Open

Managed Firewall Service, Security Operation Centre (SOC), Security Incident and Event Management (SIEM) and Incident Response Managed Service for Mercy University Hospital

Value

€900k

Deadline

04 Jul

Managed Firewall and Security Services for Mercy University Hospital over 5 years

SME fit: Medium Bid effort: Medium 📍 Cork

Managed Firewall and Security Services for Mercy University Hospital over 5 years

Bidder profile

Mid-sized to large firms with experience in public sector cybersecurity services and compliance.

Risks & flags

  • Qualification gate
  • Two-step process
  • Technical ambiguity

Briefing

AI-generated analysis of the documents. Check the official notice and any amendments for current submission details.

1. At a glance

Field Detail
Buyer Mercy University Hospital
Title Managed Firewall Service, Security Operation Centre (SOC), Security Incident and Event Management (SIEM) and Incident Response Managed Service for Mercy University Hospital
CPV / category services
Estimated value 900000.00
Per-year (if multi-year) not stated
Procedure type not stated
Lots not stated
Location Ireland
Contract length 5 years
Submission deadline 2025-07-04T11:00:00+00:00
Go-live / start not stated

2. Scope of Work

Mercy University Hospital ran this procurement for “Managed Firewall Service, Security Operation Centre (SOC), Security Incident and Event Management (SIEM) and Incident Response Managed Service for Mercy University Hospital” as an operational contract requiring implementation and sustained service execution. The extracted pack showed qualification-stage material with references to later ITT technical depth; practical activity therefore centred on building, integrating, and operating the specified service stack with compliant reporting and handover obligations where stated. Constituent activities and named work elements in the supplied extracts:

  • Title: Managed Firewall Service, Security Operation Centre (SOC), Security Incident and Event Management (SIEM) and Incident Response Managed Service for Mercy University Hospital
  • be required to hold for the term of the Services Contract the following insurances: Type of Insurance Indemnity Limit Employer’s Liability €13 million Public Liability €6.5 million Product Liability €6
  • rity estimates that the expenditure on the Services to be covered by the proposed Service Contract may amount to some €900,000 (excl
  • r must have a proven track record in delivering Managed Firewall Services for a minimum of 3-5 years
  • rer shall be required to supply its Tax Clearance Access Number and Tax Reference Number to facilitate online verification of their tax status by
  • Service requirements delivered/in place within 2 months of contract signing
  • ce of minor function is degraded 8am-8pm, Monday-Friday 1 day 3 days Service Request Service
  • 24*7 2 hours 4 hours Priority 3 8*5 4 hours 3 days Priority 4 / Service Requests 8*
  • hours Priority 3 8*5(9am-5pm local time) 4 hours 3 days Priority 4 / Service Requests 8*
  • echnical and Service requirements delivered/in place within 2 months of contract signing
  • Firewall Professional Service (20 days per year) NaN NaN NaN NaN NaN
  • Engineering SIEM Professional Service (20 days Per year) NaN NaN NaN NaN NaN Non-binding monetary references in the source were treated as context only and were not used as qualification thresholds.

3. Background & buyer context

The buyer context reflected a formal Irish public-procurement route, with pre-qualification used to control entry into the tender stage.

  • 1.7 Contracting Authority policy seeks to encourage participation on a fair and equal basis by Small and Medium Enterprises (“SME”s) in this Competition. SMEs that believe the scope of this Competition is
  • 1.7 Contracting Authority policy seeks to encourage participation on a fair and equal basis by Small and Medium Enterprises (“SME”s) in this Competition. SMEs that believe the scope of this Competition is beyond their technical or business capacity are encouraged, subject to paragraph 2.5, to explore the possibilities of forming relationships with other SMEs or with larger enterprises. Through such relationships they can participate and contribute to the successful implementation of any Services Contract that may result from this Competition and therefore increase their social and economic benefits. Larger enterprises are also encouraged, subject to paragraph 2.5, to consider the practical ways that SMEs can be included in their proposals to maximise the social and economic benefits of any Services Contracts that may result from this Competition.

4. Eligibility & selection criteria

  • Turnover requirement — — use these verbatim for insurance / turnover. If a category (insurance, turnover) has no entry here, treat it as 'not specified' for THIS tender.
  • Insurance — — use these verbatim for insurance / turnover. If a category (insurance, turnover) has no entry here, treat it as 'not specified' for THIS tender.; be required to hold for the term of the Services Contract the following insurances: Type of Insurance Indemnity Limit Employer’s Liability €13 million Public Liability €6.5 million Product Liability €6; 5 million Professional Indemnity €1 million Cyber Security €2.5 million 2
  • Certifications — not specified for this tender
  • Past experience — not specified for this tender
  • Personnel — not specified for this tender
  • Geographic / facility constraints — not specified for this tender Additional binding lines surfaced in the deterministic extract:
  • — use these verbatim for insurance / turnover. If a category (insurance, turnover) has no entry here, treat it as 'not specified' for THIS tender.
  • be required to hold for the term of the Services Contract the following insurances: Type of Insurance Indemnity Limit Employer’s Liability €13 million Public Liability €6.5 million Product Liability €6
  • 5 million Professional Indemnity €1 million Cyber Security €2.5 million 2

5. Award criteria & scoring

Criterion Weight (%) Sub-criteria Pass/fail threshold
[MUH Firewall SOC SIEM RFT Final D.docx] EU) No 833/2014 (as amended by EU Regul 10% not stated not stated
The documents indicated a staged process (qualification, then tender). Any explicit MEAT split is captured above where a numeric line was visible; otherwise it remained not specified in the provided text extract.

6. Submission requirements

  • Method statement / response document (template/page limits) — Appendix 1 questionnaire/PQQ response was required.
  • CVs (page count, named roles) — not specified in extract.
  • Pricing schedule (format/template) — expected at ITT stage.
  • Case studies (number/value range) — client references/comparable project evidence was referenced.
  • Declarations (ESPD/Bona Fides/Tax/COI) — ESPD/declaration/statement-of-confirmation language was present.
  • Mandatory site visit — not specified in extract.
  • Submission portal and formatting — eTenders portal and PDF electronic copies were referenced. Submission-related source lines:
  • Appendix 1: Requirements and Specifications
  • Appendix 4: Declaration as to Personal Circumstances of Tenderer
  • Appendix 6: Confidentiality Agreement
  • 1.1 Mercy University Hospital (MUH) (the “Contracting Authority”) wishes to establish a Single Party Framework Agreement and invites tenders (“Tenders”) to this request for tenders (“RFT”) from economic operators (“Tenderers”) for the provision of the services as described in Appendix 1 to this RFT (the “Services”).
  • [MUH Firewall SOC SIEM RFT Final D.docx] Regulation (EU) 2016/679 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (the “General Data Protection Regulation”), and any guidelines and codes of practice issued by the Office of the Data Protection Commission or other supervisory authority for data protection in Ireland from time to time. The Contracting Authority will be a Data Controller (where Data Controller has the meaning given under the Data Protection Laws) in respect of any Personal Data (where Personal Data has the meaning given under the Data Protection Laws) required to be provided by the Tenderer in response to this RFT. The Tenderer, as Data Controller in respect of any Personal Data provided by it in its Tender, is required to confirm in the statement required under paragraph 2.4 below that all Data Subjects (where Data Subject has the meaning given under the Data Protection Laws) whose Personal Data is provided by the Tenderer have consented to the processing of such Personal Data by the Tenderer, the Contracting Authority, the Evaluation Team and the supplier of the etenders.gov.ie website, for the purposes of the participation of the Tenderer in this Competition or that the Tenderer otherwise has a legal basis for providing such Personal Data to the Contracting Authority for the purposes of its participation in this Competition.
  • [MUH Firewall SOC SIEM RFT Final D.docx] markets and procedures supporting negotiations on access of Union economic operators, goods and services to the public procurement and concession markets of third countries (International Procurement Instrument – IPI), and to their obligation to comply therewith. In particular, tenderers and candidates should note in Article 6 of Regulation (EU) 2022/1031, the obligations for a Contracting Authority in the context of a procurement procedure where the EU Commission has adopted an IPI measure. Tenderers are referred to the provisions of Regulation (EU) 2022/2560 of the European Parliament and of the Council on Foreign Subsidies distorting the Internal Market, in addition to Commission Implementing Regulation (EU) 2023/1441, and their obligation to comply therewith. In particular, tenderers and candidates should note the requirements in Articles 28 and 29 of Regulation (EU) 2022/2560 relating to the prior notification or declaration of foreign financial contributions, where the estimated value of the public procurement procedure is equal to or greater than the applicable financial thresholds set out therein. In that regard, Tenderers and Candidates are referred to Appendix 3A of the RFT.

7. Key dates & process

Milestone Date
RFT issued not specified
Clarification deadline not specified
Mandatory site visit not specified
Tender deadline (date + time) 2025-07-04T11:00:00+00:00
Expected award not specified
Contract start not specified
Go-live / mobilisation not stated
Date surfaced in documents 2025-07-04T11:00:00+00:00
Date surfaced in documents 12 March 2001
Date surfaced in documents 31 July 2014
Date surfaced in documents Regulations 2016

8. Contract terms that matter

Contract duration in the extract: 5 years. Payment cycle, SLA/KPI schedule, and penalty regime were not fully disclosed in the snippets unless listed below.

  • VERIFIED PHRASES (deterministic regex extract from the documents — treat as authoritative for numerical claims)
  • be required to hold for the term of the Services Contract the following insurances: Type of Insurance Indemnity Limit Employer’s Liability €13 million Public Liability €6.5 million Product Liability €6
  • NOW IT IS HEREBY AGREED in consideration of the sum of €2.00 (the receipt of which is hereby acknowledged by the Contractor) as follows:
  • e right to extend the Term for a period or periods of up to 12 months with a maximum of 2 such extension or e
  • es for ten (10) calendar days either Party may terminate at 14 days notice
  • breach(es) (if the breach(es) are capable of remedy) within 30 days after receipt of a request in writing f
  • For the Term and for a period of 12 months thereafter (and save in respect of publ
  • [MUH Firewall SOC SIEM RFT Final D.docx] Description: mercy

9. Risks, red flags & unusuals

  • Qualification gate: the deterministic extract included a turnover threshold line (— use these verbatim for insurance / turnover. If a category (insurance, turnover) has no entry here, treat it as 'not specified' for THIS tender.), which can materially narrow bidder pool composition.
  • The two-step process (PQQ then ITT) shifted effort to compliance evidence early, with competitive scoring detail potentially deferred.
  • Technical and contractual granularity appeared ITT-dependent, increasing ambiguity at qualification stage for non-incumbent bidders.

10. SME fit assessment

This competition looked most accessible to firms with established public-sector tender capability, documented financial capacity, and direct operational experience in the relevant service category.

  • Credible bidder profile — mid-sized to large specialist with formal QA/compliance process.
  • Consortium / sub-contracting — allowed or addressed in the extracts (Appendix references and reliance provisions).
  • Indicative bid-prep effort — 6 to 12 working days for evidence collation, form completion, and review cycles at PQQ level.
  • Pwin signal — strongest for bidders with reusable qualification artefacts, comparable references, and low-friction mobilisation capability.

11. Where to dig deeper

  • Source RFT/PQQ filenames: MUH Firewall SOC SIEM RFT Final D.docx, RFT Final D.docx] Description: mercy, RFT Final D.docx] Part 1: Introduction.
  • eTenders CFT / notice reference: not specified in extract.
  • Clarification contact / portal: eTenders message portal (email not surfaced in extract).
  • Key attachments to prioritise: Appendix 1: Requirements and Specifications, Appendix 2: Pricing Schedule, Appendix 3: Tenderer’s Statement.

Can you bid?

Public liability insurance

€6,500,000

Professional indemnity insurance

€1,000,000

Scoring

Most Economically Advantageous Tender

Cost

Technical and Operational Compliance

Lots (1)

Lot 1: Firewall, SOC, and SIEM Services

Provision of Firewall, Security Operations Centre, and Security Information and Event Management services for Mercy University Hospital.

Documents (2)

DOCX

MUH Firewall SOC SIEM RFT Final D.docx

1.1 MB · RFT / Invitation to Tender

XLSX

MUHPricingSchedule.xlsx

27.6 KB · Pricing / BOQ / Schedule of Rates

Original notice text

Provision of managed firewall services, SOC, SIEM, and incident response for Mercy University Hospital, ensuring compliance and operational effectiveness over a 5-year contract.

AI analysis updated 4 months ago

Bid ↗
Details

Value

€900k

Deadline

04 Jul

View on eTenders ↗

Location

Services to be provided across Ireland.

Procedure

Open

Clarification

27 Jun 2025

eTenders ID

5781074

✦ Ask AI about this tender

Ask AI

Knows this tender's documents

Is this a good fit for us?
Based on the deadline, buyer, and eligibility requirements in the tender documents, here's a quick read on fit — with citations back to the exact clause 1 so you can verify it yourself.

Example only — sign up to ask about this tender