Single Party Framework Agreement for the provision of a New Firewall, Security Operation Centre (SOC) and Security Incident and Event Management (SIEM)
Value
€900k
Deadline
25 Oct
25 Oct 2024
Value
€900k
Deadline
25 Oct
Framework for cybersecurity services including firewall, SOC, and SIEM for NTPF.
Framework for cybersecurity services including firewall, SOC, and SIEM for NTPF.
Bidder profile
Firms with experience in cybersecurity services, particularly in firewall, SOC, and SIEM implementations, are encouraged to apply.
Risks & flags
- Turnover threshold may limit participation
- Geographic constraints
- Tight implementation timeline
- Single supplier framework risks
Briefing
AI-generated analysis of the documents. Check the official notice and any amendments for current submission details.
1. At a glance
| Buyer | National Treatment Purchase Fund |
|---|---|
| Title | Single Party Framework Agreement for the provision of a New Firewall, Security Operation Centre (SOC) and Security Incident and Event Management (SIEM) |
| CPV / category | IT & Software / services |
| Estimated value | €900,000 |
| Per-year (if multi-year) | not stated |
| Procedure type | Open procedure |
| Lots | not stated |
| Location | not stated |
| Contract length | 3 years (with possible 2 extensions of 12 months each) |
| Submission deadline | 25 October 2024, 11:00 AM |
| Go-live / start | not stated |
2. Scope of Work
The National Treatment Purchase Fund (NTPF) seeks a contractor to provide a comprehensive suite of cybersecurity services, including a new firewall, a Security Operation Centre (SOC), and Security Incident and Event Management (SIEM) capabilities. The contractor will be responsible for ensuring the security and integrity of the NTPF's IT infrastructure and data.
The key activities involved in this contract include:
- Firewall Implementation: Deploying a new firewall system that meets specified hardware requirements, including 8 x 1Gbps interfaces and 4 x 10Gbps expansion slots.
- SOC Operations: Establishing a Security Operation Centre that operates 24/7 to monitor, detect, and respond to security incidents.
- SIEM Services: Implementing a Security Incident and Event Management system that retains logs for a minimum of 6 months and a maximum of 12 months, with protocols for irrevocable destruction post-retention.
- Incident Response Management: Providing managed services for incident response, including conducting a minimum of one penetration test annually and demonstrating appropriate remediation of findings.
- Regular Reporting: Conducting monthly, quarterly, and annual review meetings to assess security posture and compliance with service level agreements (SLAs).
- Compliance and Standards: Adhering to relevant cybersecurity standards and regulations, including ISO27001.
The contractor must ensure that all services are operational within 2 months of contract signing.
3. Background & buyer context
The procurement of these services aligns with the NTPF's strategic objective to enhance its cybersecurity framework in response to increasing threats in the digital landscape. This initiative is part of a broader government policy aimed at strengthening the cybersecurity posture of public sector organizations. The NTPF has historically relied on external providers for cybersecurity services, and this tender aims to establish a long-term partnership with a single provider to ensure consistency and reliability in service delivery.
4. Eligibility & selection criteria
Bidders must meet the following eligibility and selection criteria:
- Turnover requirement: Minimum average annual turnover of €1,800,000 in the last three financial years.
- Insurance:
- Employer’s Liability: €13 million
- Public Liability: €6.5 million
- Product Liability: €6.5 million
- Professional Indemnity: €1 million
- Cyber Security: €2.5 million
- Certifications: Compliance with ISO27001 or equivalent standards.
- Past experience: Completion of a minimum of 2 comparable projects within the last 5 years, demonstrating similar size and complexity.
- Personnel: At least one cybersecurity specialist with a minimum of 5 years’ experience in SOC operations.
- Geographic / facility constraints: Services must be deliverable within the Republic of Ireland.
5. Award criteria & scoring
Bids will be evaluated based on the following criteria:
| Criterion | Weight (%) | Sub-criteria | Pass/Fail Thresholds |
|---|---|---|---|
| Price | 60 | Total cost of the solution | None specified |
| Quality | 40 | Technical compliance, experience, and methodology | None specified |
The evaluation will follow the Most Economically Advantageous Tender (MEAT) principle, focusing on the best balance of price and quality.
6. Submission requirements
Bidders must submit the following documentation:
- Method statement / response document: Follow the provided template with a maximum of 20 pages.
- CVs: For key personnel, limited to 2 pages each.
- Pricing schedule: Must use the specified template.
- Case studies: At least 2 examples of relevant projects, with values ranging from €100,000 to €500,000.
- Declarations: Including ESPD, Bona Fides, Tax clearance, and Conflict of Interest statements.
- Mandatory site visit: Not required for this tender.
- Submission portal: All documents must be submitted via the electronic tenderbox on eTenders.gov.ie.
7. Key dates & process
| Event | Date |
|---|---|
| RFT issued | 26 September 2024 |
| Clarification deadline | 11 October 2024, 17:30 |
| Tender deadline | 25 October 2024, 12:00 |
| Expected award | Not specified |
| Contract start | Not specified |
| Go-live / mobilisation | Not specified |
8. Contract terms that matter
The contract will have a term of 3 years, with the possibility of extending for up to 2 additional years, each for 12 months. Key terms include:
- Payment terms: Payments will be made in accordance with the Services Contract at Appendix 5.
- Service Level Agreements (SLAs): Specific performance metrics will be established, including response times for incidents.
- Liquidated damages: May apply for failure to meet SLAs.
- Termination clauses: The NTPF reserves the right to terminate the contract for material breaches.
- Intellectual Property (IP) ownership: All IP developed during the contract will remain with the NTPF.
- Sub-contracting rules: Sub-contracting is permitted but must be disclosed in the tender submission.
9. Risks, red flags & unusuals
Potential risks associated with this tender include:
- Turnover threshold: The minimum turnover requirement of €1,800,000 may limit participation from smaller firms.
- Geographic constraints: Services must be deliverable within Ireland, which may exclude international firms.
- Tight implementation timeline: Services must be operational within 2 months of contract signing, which may be challenging for some bidders.
- Single supplier framework: This may lead to a lack of competitive tension in pricing and service delivery.
10. SME fit assessment
This tender is suitable for small to medium-sized enterprises (SMEs) with experience in cybersecurity services. Viable bidders should have:
- A proven track record in implementing firewall, SOC, and SIEM solutions.
- The necessary certifications, such as ISO27001.
- The capacity to manage a contract of this scale, including the ability to meet the turnover requirement.
Consortium arrangements are allowed, enabling smaller firms to collaborate with larger enterprises. The indicative bid preparation effort is estimated at 10-15 days, considering the documentation and compliance requirements. The presence of a minimum turnover requirement and the potential for a single supplier framework may indicate a competitive advantage for incumbents.
11. Where to dig deeper
- Source RFT filename: Call for Tender - NTPF Firewall SOC SIEM 26.09.24.docx
- eTenders CFT ID: Not specified
- Contact email: Queries must be directed through the messaging facility on eTenders.gov.ie
- Important attachments:
- Appendix 1: Requirements and Specifications
- Appendix 2: Pricing Schedule
- Appendix 5: Services Contract
This tender has been awarded
- Presidio Europe Limited trading as Arkphire Security Limited · 24 Dec 2024
- Simply Zesty Ltd · 16 May 2024
Can you bid?
Required certifications
- ISO27001
Minimum turnover
€1,800,000
Public liability insurance
€6,500,000
Professional indemnity insurance
€1,000,000
Named standards / methodologies
Scoring
Most Economically Advantageous Tender
Documents (4)
Call for Tender - NTPF Firewall SOC SIEM 26.09.24.docx
1.5 MB · RFT / Invitation to Tender
NTPFPricingSchedule.xlsx
21.7 KB · Pricing / BOQ / Schedule of Rates
NTPF Single-Operator Framework Agreement Terms - Final.docx
93.3 KB · Contract / Agreement / Terms
NTPF Tender Response Document Final.docx
163.7 KB · Tender Response Template
Original notice text
The National Treatment Purchase Fund seeks a contractor to provide cybersecurity services, including a new firewall, SOC operations, and SIEM capabilities, ensuring the security of its IT infrastructure.
AI analysis updated 3 months, 4 weeks ago
Value
€900k
Deadline
25 Oct
Location
Services must be deliverable within the Republic of Ireland.
Procedure
Open
Clarification
11 Oct 2024
eTenders ID
4384225
Ask AI
Knows this tender's documents
Example only — sign up to ask about this tender