Provision of Chief Information Security Officer Function and Related Services, National Library of Ireland
Value
€120k
Deadline
04 Apr
04 Apr 2024
Value
€120k
Deadline
04 Apr
CISO function and related services for the National Library of Ireland over 12 months
CISO function and related services for the National Library of Ireland over 12 months
Bidder profile
Mid-sized to large firms with experience in public sector information security services and compliance.
Risks & flags
- Qualification gate
- Two-step process
- Compliance evidence requirements
Briefing
AI-generated analysis of the documents. Check the official notice and any amendments for current submission details.
1. At a glance
| Field | Detail |
|---|---|
| Buyer | National Library of Ireland |
| Title | Provision of Chief Information Security Officer Function and Related Services, National Library of Ireland |
| CPV / category | services |
| Estimated value | 120000.00 |
| Per-year (if multi-year) | not stated |
| Procedure type | not stated |
| Lots | not stated |
| Location | Ireland |
| Contract length | 12 months |
| Submission deadline | 2024-04-04T11:00:00+00:00 |
| Go-live / start | not stated |
2. Scope of Work
National Library of Ireland ran this procurement for “Provision of Chief Information Security Officer Function and Related Services, National Library of Ireland” as an operational contract requiring implementation and sustained service execution. The extracted pack showed qualification-stage material with references to later ITT technical depth; practical activity therefore centred on building, integrating, and operating the specified service stack with compliant reporting and handover obligations where stated. Constituent activities and named work elements in the supplied extracts:
- Title: Provision of Chief Information Security Officer Function and Related Services, National Library of Ireland
- ority estimates that the expenditure on the Services to be covered by the proposed Services Contract may amount to some €120,000 (excl
- Minimum Requirement 1: Tenderers must declare by way of ESPD that they have successfully delivered a minimum of three (3) contracts of a similar nature to the Services required in Appendix 1 in the last five (5) years
- Minimum Requirement 2: Tenderers must provide the following supporting documentation in their Tender response document
- Details of a successful delivery of a minimum of three (3) contracts of a similar nature to the Services required in Appendix 1 of this RFT in the last five (5) years
- Minimum Requirement 1: Tenderers are required to provide details in terms of supporting documentation/evidence of certification to an internationally recognised standard for information security management (e
- rer shall be required to supply its Tax Clearance Access Number and Tax Reference Number to facilitate online verification of their tax status by
- ISO 27001/2series certification (or equivalent) for Cloud Security Systems
- on is to continue the services contract up to an additional 24 months
- tion (the “Services Contract”) will be issued for a term of 12 months (“the Term”)
- Appendix 4: Declaration as to Personal Circumstances of Tenderer Appendix 5: Services Contract
- Prior to and as a condition of award of any Services Contract, the successful Tenderer shall be required to designate a Non-binding monetary references in the source were treated as context only and were not used as qualification thresholds.
3. Background & buyer context
The buyer context reflected a formal Irish public-procurement route, with pre-qualification used to control entry into the tender stage.
- Background & Current Infrastructure
- Policy & key documentation update & remediation, in particular: Information Asset Register, Disaster recovery & Incident Response, Data Classification, Data Retention & Data Loss Prevention
- Work with the NLI’s Head of Digital Collections, CRO, and other senior managers to identify, assess, and remediate policy, documentation and process gaps.
4. Eligibility & selection criteria
- Turnover requirement — — use these verbatim for insurance / turnover. If a category (insurance, turnover) has no entry here, treat it as 'not specified' for THIS tender.
- Insurance — — use these verbatim for insurance / turnover. If a category (insurance, turnover) has no entry here, treat it as 'not specified' for THIS tender.; Type of Insurance Indemnity Limit Type of Insurance Indemnity Limit Employer’s Liability €13 million Public Liability €6.5 million Professional Indemnity €1 millio
- Certifications — not specified for this tender
- Past experience — not specified for this tender
- Personnel — not specified for this tender
- Geographic / facility constraints — not specified for this tender Additional binding lines surfaced in the deterministic extract:
- — use these verbatim for insurance / turnover. If a category (insurance, turnover) has no entry here, treat it as 'not specified' for THIS tender.
- Type of Insurance Indemnity Limit Type of Insurance Indemnity Limit Employer’s Liability €13 million Public Liability €6.5 million Professional Indemnity €1 millio
5. Award criteria & scoring
| Criterion | Weight (%) | Sub-criteria | Pass/fail threshold |
|---|---|---|---|
| If a Tenderer does not, upon request by the Contracting Authority, provide evide | 10% | not stated | not stated |
| The documents indicated a staged process (qualification, then tender). Any explicit MEAT split is captured above where a numeric line was visible; otherwise it remained not specified in the provided text extract. |
6. Submission requirements
- Method statement / response document (template/page limits) — Appendix 1 questionnaire/PQQ response was required.
- CVs (page count, named roles) — not specified in extract.
- Pricing schedule (format/template) — expected at ITT stage.
- Case studies (number/value range) — client references/comparable project evidence was referenced.
- Declarations (ESPD/Bona Fides/Tax/COI) — ESPD/declaration/statement-of-confirmation language was present.
- Mandatory site visit — not specified in extract.
- Submission portal and formatting — eTenders portal and PDF electronic copies were referenced. Submission-related source lines:
- Using the Minimum Turnover Requirements template table below, Tenderers must submit a Statement from an Independent Accountant or Auditor for the past three years
- Minimum Requirement 1: Tenderers must declare by way of ESPD that they have successfully delivered a minimum of three (3) contracts of a similar nature to the Services required in Appendix 1 in the last five (5) years
- Details of a successful delivery of a minimum of three (3) contracts of a similar nature to the Services required in Appendix 1 of this RFT in the last five (5) years
- Appendix 1: Requirements and Specifications
- Appendix 4: Declaration as to Personal Circumstances of Tenderer Appendix 5: Services Contract
- Appendix 6: Confidentiality Agreement
7. Key dates & process
| Milestone | Date |
|---|---|
| RFT issued | not specified |
| Clarification deadline | not specified |
| Mandatory site visit | not specified |
| Tender deadline (date + time) | 2024-04-04T11:00:00+00:00 |
| Expected award | not specified |
| Contract start | not specified |
| Go-live / mobilisation | not stated |
| Date surfaced in documents | 2024-04-04T11:00:00+00:00 |
| Date surfaced in documents | 28 March 2024 |
| Date surfaced in documents | 31 July 2014 |
| Date surfaced in documents | March 2024 |
8. Contract terms that matter
Contract duration in the extract: 12 months. Payment cycle, SLA/KPI schedule, and penalty regime were not fully disclosed in the snippets unless listed below.
- VERIFIED PHRASES (deterministic regex extract from the documents — treat as authoritative for numerical claims)
- NOW IT IS HEREBY AGREED in consideration of the sum of €2.00 (the receipt of which is hereby acknowledged by the Contractor) as follows:
- Minimum Requirement 1: Tenderers are required to provide details in terms of supporting documentation/evidence of certification to an internationally recognised standard for information security management (e
- tion (the “Services Contract”) will be issued for a term of 12 months (“the Term”)
- e right to extend the Term for a period or periods of up to 12 months with a maximum of two (2) such extensio
- [insert number]calendar days either Party may terminate at 14 days’ notice
- breach(es) (if the breach(es) are capable of remedy) within 30 days after receipt of a request in writing f
- For the Term and for a period of 12 months thereafter (and save in respect of publ
9. Risks, red flags & unusuals
- Qualification gate: the deterministic extract included a turnover threshold line (— use these verbatim for insurance / turnover. If a category (insurance, turnover) has no entry here, treat it as 'not specified' for THIS tender.), which can materially narrow bidder pool composition.
- The two-step process (PQQ then ITT) shifted effort to compliance evidence early, with competitive scoring detail potentially deferred.
- Technical and contractual granularity appeared ITT-dependent, increasing ambiguity at qualification stage for non-incumbent bidders.
10. SME fit assessment
This competition looked most accessible to firms with established public-sector tender capability, documented financial capacity, and direct operational experience in the relevant service category.
- Credible bidder profile — mid-sized to large specialist with formal QA/compliance process.
- Consortium / sub-contracting — allowed or addressed in the extracts (Appendix references and reliance provisions).
- Indicative bid-prep effort — 6 to 12 working days for evidence collation, form completion, and review cycles at PQQ level.
- Pwin signal — strongest for bidders with reusable qualification artefacts, comparable references, and low-friction mobilisation capability.
11. Where to dig deeper
- Source RFT/PQQ filenames: NLI-DC-24001 Chief Information Officer (CISO) (002).docx, Appendix 1 in the last five (5) years, Appendix 1 of this RFT in the last five (5) years.
- eTenders CFT / notice reference: not specified in extract.
- Clarification contact / portal: eTenders message portal (email not surfaced in extract).
- Key attachments to prioritise: Appendix 1: Requirements and Specifications, Appendix 2: Pricing Schedule, Appendix 3: Tenderer’s Statement.
This tender has been awarded
- VISO Cyber Security · 09 Jul 2024
- VISO Cyber Security · 21 May 2024
Can you bid?
Required certifications
- ISO 27001
Public liability insurance
€6,500,000
Professional indemnity insurance
€1,000,000
Scoring
Most Economically Advantageous Tender
Understanding the Requirement
Reporting
Ultimate Cost
Lots (1)
Delivery of CISO services including cybersecurity expertise, incident response, and network analysis.
Documents (4)
NLI-DC-24001 Chief Information Officer (CISO) (002).docx
623.1 KB · RFT / Invitation to Tender
Appendix 2 Pricing Schedule.xlsx
13.0 KB · Pricing / BOQ / Schedule of Rates
Espd.docx
139.4 KB · ESPD (European Single Procurement Document)
NLI TRD for Provision of Chief Information Security Officer Function and Related Services..docx
105.4 KB · Tender Response Template
Original notice text
The National Library of Ireland seeks a provider for Chief Information Security Officer services, focusing on implementation and ongoing management of security protocols and compliance reporting.
AI analysis updated 4 months ago
Value
€120k
Deadline
04 Apr
Location
Ireland
Procedure
Open
Clarification
28 Mar 2024
eTenders ID
3172368
Ask AI
Knows this tender's documents
Example only — sign up to ask about this tender