Skip to content
TenderMatch
The recorded submission deadline has passed. Find open opportunities. Check the official notice for amendments.
← Tenders / Request for Tenders for the provision of ISO Audit and Training Services for the certification of the OGCIO's Information Security Management System to the requirements of the ISO 27001:2022 Standard
Closed Professional Consultancy Services Open

Request for Tenders for the provision of ISO Audit and Training Services for the certification of the OGCIO's Information Security Management System to the requirements of the ISO 27001:2022 Standard

Value

€120k

Deadline

15 Oct

Provision of ISO audit and training services for OGCIO's ISMS certification

SME fit: Low Bid effort: Medium

Provision of ISO audit and training services for OGCIO's ISMS certification

Bidder profile

Firms with experience in ISO auditing and training, particularly with large organizations, are preferred.

Risks & flags

  • High turnover requirement
  • Experience with large organizations required
  • Ambiguity in SLAs/KPIs

Briefing

AI-generated analysis of the documents. Check the official notice and any amendments for current submission details.

1. At a glance

Buyer Office of the Government Chief Information Officer
Title Request for Tenders for the provision of ISO Audit and Training Services for the certification of the OGCIO's Information Security Management System to the requirements of the ISO 27001:2022 Standard
CPV / category Professional Consultancy / Services
Estimated value €120,000
Per-year not stated
Procedure type Open procedure
Lots not stated
Location not stated
Contract length 36 months, with possible extensions
Submission deadline 15 October 2024, 14:00
Go-live / start not stated

2. Scope of Work

The contract involves providing ISO audit and training services to certify the Office of the Government Chief Information Officer's (OGCIO) Information Security Management System (ISMS) according to the ISO 27001:2022 standard. The estimated expenditure for the services is €120,000 over the contract term, which is 36 months, with the possibility of two 12-month extensions.

The contractor's day-to-day activities will include:

  • Conducting ISO 27001:2022 audits to assess compliance with the standard.
  • Providing training sessions on ISO 27001:2022, including:
  • One-day introduction courses.
  • One-day transition training.
  • Two-day implementation courses.
  • Two-day internal auditor training.
  • Five-day lead auditor training.
  • Preparing audit reports and documentation for the OGCIO.
  • Liaising with OGCIO personnel to ensure understanding and compliance with ISO standards.
  • Supporting the transition from ISO 27001:2013 certification to ISO 27001:2022 certification.

The contractor must have experience with similar organizations, specifically those with over 1,000 employees, and must have conducted a minimum of two ISO 27001 assessments in the past three years.

3. Background & buyer context

This procurement is initiated to ensure that the OGCIO's ISMS remains compliant with the updated ISO 27001:2022 standard, as the current certification (ISO 27001:2013) is valid until 10 January 2025. The OGCIO is part of the Department of Public Expenditure National Development Plan Delivery and Reform, which emphasizes the importance of information security in public administration. The strategic driver for this procurement aligns with government policies on enhancing cybersecurity and information management practices.

4. Eligibility & selection criteria

Bidders must meet the following eligibility and selection criteria:

  • Turnover requirement: Minimum average annual turnover of €250,000 for each of the last three financial years.
  • Insurance:
  • Employer’s Liability: €12.5 million limit any one claim.
  • Public Liability: €6.5 million limit any one claim.
  • Professional Indemnity: €1 million limit on aggregated number of claims per insurance year.
  • Cyber Liability: €1 million limit any one claim.
  • Product Liability: N/A.
  • Certifications: Must be accredited as a Certification Body for ISO/IEC 27001:2022.
  • Past experience: Must have conducted a minimum of two ISO 27001 assessments and training for organizations other than the OGCIO in the last three years.
  • Personnel: A Junior Auditor must have at least one year of relevant experience.
  • Geographic / facility constraints: not specified for this tender.

5. Award criteria & scoring

Bids will be evaluated based on the following criteria:

Criterion Weight (%) Sub-criteria Pass/Fail Thresholds
Technical Ability 60% Quality of audit and training services Minimum score of 60%
Financial Offer 40% Cost-effectiveness of the proposal No minimum score

The evaluation will follow the Most Economically Advantageous Tender (MEAT) principle, balancing quality and price.

6. Submission requirements

Bidders must submit the following documentation:

  • Method statement / response document: Use the provided template, with a maximum of 20 pages.
  • CVs: For key personnel, maximum of 2 pages each.
  • Pricing schedule: Must follow the format in Appendix 2.
  • Case studies: At least two, detailing projects of similar size and complexity.
  • Declarations: Including ESPD, Bona Fides, Tax clearance, and Conflict of Interest.
  • Mandatory site visit: Not specified for this tender.
  • Submission portal: All documents must be submitted via the electronic tenderbox on eTenders.

7. Key dates & process

Key Date Description
RFT issued 24 September 2024
Clarification deadline 8 October 2024, 14:00
Tender deadline 15 October 2024, 14:00
Expected award not stated
Contract start not stated
Go-live / mobilisation not stated

8. Contract terms that matter

Key contract terms include:

  • Term: 36 months, with the possibility of two 12-month extensions.
  • Payment terms: Payments will be made in accordance with the Services Contract.
  • Key SLAs/KPIs: Not specified in the documents.
  • Liquidated damages: Not specified.
  • Termination clauses: The contract may be terminated with two months' notice.
  • IP ownership: Not specified.
  • Sub-contracting rules: Allowed, but the Prime Contractor must take overall responsibility.

9. Risks, red flags & unusuals

Potential risks and concerns include:

  • The turnover requirement of €250,000 may limit participation to established firms, potentially excluding smaller SMEs.
  • The requirement for past experience with organizations of similar size (1,000+ employees) may restrict the pool of eligible bidders.
  • The lack of specified SLAs/KPIs may lead to ambiguity in performance expectations.
  • The contract's reliance on timely completion of audits and training may pose risks if the contractor fails to meet deadlines.

10. SME fit assessment

Small and medium enterprises (SMEs) that can credibly bid must:

  • Have a proven track record in ISO auditing and training, particularly with ISO 27001 standards.
  • Meet the insurance and turnover requirements, which may be challenging for smaller firms.
  • Consider forming consortia or partnerships with larger firms to enhance their bid's competitiveness.
  • Expect a bid preparation effort of approximately 10-15 days, factoring in the need for detailed documentation and case studies.
  • The presence of an incumbent or established firms in the sector may signal a lower probability of winning for new entrants.

11. Where to dig deeper

  • RFT filename: RFT for ISO Audit and Training Services (Final).docx
  • eTenders CFT ID: not specified
  • Contact email: not specified
  • Important attachments:
  • Appendix 1: Requirements and Specifications
  • Appendix 2: Pricing Schedule
  • Appendix 3: Tenderer’s Statement

Can you bid?

Required certifications

  • ISO/IEC 27001:2022

Minimum turnover

€250,000

Public liability insurance

€6,500,000

Professional indemnity insurance

€1,000,000

Scoring

Most Economically Advantageous Tender

Documents (3)

DOCX

RFT for ISO Audit and Training Services (Final).docx

165.3 KB · RFT / Invitation to Tender

XLSX

eTenders - ISO Tender - Clarification Responses.xlsx

18.6 KB · Clarification / Addendum

XLSX

eTenders - ISO Tender - Clarifications (Additional).xlsx

10.6 KB · Clarification / Addendum

Original notice text

The contract involves providing ISO audit and training services to certify the OGCIO's Information Security Management System according to ISO 27001:2022, including audits and various training courses over a 36-month period.

AI analysis updated 3 months, 4 weeks ago

Bid ↗
Details

Value

€120k

Deadline

15 Oct

View on eTenders ↗

Location

Not stated

Procedure

Open

Clarification

08 Oct 2024

eTenders ID

4377029

✦ Ask AI about this tender

Ask AI

Knows this tender's documents

Is this a good fit for us?
Based on the deadline, buyer, and eligibility requirements in the tender documents, here's a quick read on fit — with citations back to the exact clause 1 so you can verify it yourself.

Example only — sign up to ask about this tender