SOC, SIEM and Managed IR Service for Health and Safety Authority
Value
€900k
Deadline
12 Oct
12 Oct 2026
Value
€900k
Deadline
12 Oct
Procurement for a Security Operations Centre (SOC), Security Information and Event Management (SIEM), and Managed Incident Response (IR) service for the Health and Safety Authority.
HSA seeks SOC, SIEM, and Managed IR services for €900,000 over 36 months
Bidder profile
This tender is suitable for established cybersecurity service providers with significant experience in SOC, SIEM, and Managed IR, capable of meeting high turnover and insurance requirements. SMEs may participate via consortia or subcontracting.
Risks & flags
- High turnover requirement relative to contract value
- Substantial insurance requirements
- Tight transition timeline
- Potential barrier for SMEs despite encouragement
Briefing
AI-generated analysis of the documents. Check the official notice and any amendments for current submission details.
1. At a glance
| Buyer | Health and Safety Authority |
|---|---|
| Title | SOC, SIEM and Managed IR Service |
| CPV / category | Not specified |
| Estimated value | €900,000 |
| Per-year (if multi-year) | €300,000 |
| Procedure type | Open procedure |
| Lots | Not specified |
| Location | Ireland |
| Contract length | 36 months |
| Submission deadline | 2026-10-12 16:00 |
| Go-live / start | Not specified |
2. Scope of Work
The Health and Safety Authority (HSA) requires a Security Operations Centre (SOC), Security Information and Event Management (SIEM), and Managed Incident Response (IR) service. The estimated expenditure for these services over the contract term, including potential extensions, is €900,000 (excluding VAT). The contract duration is 36 months, with an option for up to two extensions of 12 months each.
The core components of the required service include:
- Security Operations Centre (SOC): This involves the continuous monitoring of the Authority's IT infrastructure and security systems. The SOC will be responsible for detecting, analysing, and responding to security threats and incidents in real-time.
- Security Information and Event Management (SIEM): A SIEM system is required to collect, aggregate, and analyse security logs and event data from various sources across the Authority's network. This will enable threat detection, compliance reporting, and forensic analysis. The service must include User and Entity Behaviour Analysis (UEBA) capabilities.
- Managed Incident Response (IR): This component covers the end-to-end management of security incidents. It includes investigation, containment, eradication, and recovery from security breaches. The service must provide detailed reporting, including Root Cause Analysis, for a minimum of 6 months and a maximum of 12 months post-incident, with log file retention for a specified period.
- Threat Intelligence and Hunting: Proactive threat hunting and the integration of threat intelligence feeds are required to identify and mitigate emerging threats before they impact the Authority's systems.
- Reporting: Regular reporting is mandated, including monthly, quarterly, and annual review meetings. Specific reporting requirements for incidents and overall security posture will be detailed.
- Transition: A managed service operational within 8 weeks of contract signing is required. Technical and service requirements must be delivered within 3 months of contract signing.
- Resilience and Compliance: The service must ensure Disaster Recovery (DR) resilience and compliance with relevant regulations.
The service provider will be expected to manage the SIEM platform and provide the SOC and IR functions. The Authority seeks a comprehensive solution to enhance its cybersecurity posture.
3. Background & buyer context
This procurement is initiated by the Health and Safety Authority (HSA) to establish a Security Operations Centre (SOC), Security Information and Event Management (SIEM), and Managed Incident Response (IR) service. The estimated value of the contract is €900,000 over an initial 36-month term, with potential for extensions. The HSA is seeking to enhance its cybersecurity capabilities and ensure the protection of its IT infrastructure and data. The procurement is being conducted under an open procedure, indicating a desire to attract a broad range of potential suppliers. The Authority's policy encourages participation by Small and Medium Enterprises (SMEs), suggesting a willingness to consider consortia or subcontracting arrangements to facilitate SME involvement.
4. Eligibility & selection criteria
Bidders must meet the following criteria to be considered:
- Turnover requirement:
- Average annual turnover of €1,800,000 for the last 3 financial years, confirmed by an auditor/accountant's statement.
- Insurance:
- Employer’s Liability: €13 million
- Public Liability: €6.5 million
- Product Liability: €6.5 million
- Professional Indemnity: €1 million
- Cyber Security: €2.5 million
- Certifications:
- ISO 27001 certification for SOC SIEM Managed Service, issued by an appropriately accredited body.
- Past experience:
- Not specified for this tender.
- Personnel:
- Not specified for this tender.
- Geographic / facility constraints:
- Technical and service requirements delivered/in place within 3 months of contract signing.
- Insurance policies must include Ireland within their territorial limits and jurisdiction.
5. Award criteria & scoring
The contract will be awarded based on the most economically advantageous tender, determined by a combination of cost and qualitative criteria. The total score is 10,000 points, with Cost accounting for 3,000 points and Qualitative Criteria for 7,000 points.
| Award Criteria | Weight (%) | Sub-criteria | Minimum Score Required |
|---|---|---|---|
| Cost (A) | 3,000 | Lowest cost receives maximum score | - |
| Qualitative (Total) | 7,000 | 3,500 | |
| Technical (B) | 2,000 | SIEM (B1: 1250), Threat Intel (B2: 500), Reporting (B3: 250) | 1,000 |
| Services (C) | 4,000 | Experience (C1: 150), SOC (C2: 1500), Incident Mgmt (C3: 500), Incident Response (C4: 1000), DR/Compliance (C5: 850) | 2,000 |
| Transition (D) | 1,000 | Transition plan | 500 |
The lowest cost tender that meets all minimum qualitative requirements receives the maximum cost score.
6. Submission requirements
Bidders must submit the following:
- European Single Procurement Document (eESPD): Electronic version, confirming compliance with exclusion grounds and selection criteria.
- Method statement / response document: Not specified by template or page limit.
- CVs: Not specified.
- Pricing schedule: Appendix 2, all-inclusive Euro prices, exclusive of VAT. Prices must remain valid for 6 months from the tender deadline.
- Case studies: Not specified.
- Declarations:
- Tenderer’s Statement (Appendix 3), signed on letterhead.
- Declaration as to Personal Circumstances (Appendix 4).
- Tax Clearance Access Number and Tax Reference Number for online verification.
- Conflict of Interest declaration.
- Mandatory site visit: Not specified.
- Submission portal: www.etenders.gov.ie electronic tenderbox. File size limit 250MB per file, 2GB total. Tenders must be in English.
7. Key dates & process
| Event | Date / Time |
|---|---|
| RFT issued | 28/08/2026 |
| Clarification deadline | 22/09/2026 17:00 |
| Mandatory site visit | Not specified |
| Tender deadline | 12/10/2026 17:00 |
| Expected award | Not specified |
| Contract start | Not specified |
| Go-live / mobilisation | Not specified |
8. Contract terms that matter
- Term: 36 months, with an option for up to two 12-month extensions.
- Payment terms: Subject to the Services Contract (Appendix 5). Invoices are deemed accepted if no queries are raised within 14 days.
- Key SLAs/KPIs: Not detailed in the provided extract, but implied through the award criteria for SOC, Incident Management, and Incident Response.
- Liquidated damages or penalty regimes: Not specified.
- Termination clauses: Either party may terminate with 14 days' notice in certain circumstances. Breach remediation is allowed within 30 days of a written request.
- IP ownership: Not specified.
- Sub-contracting rules: Subcontractors must submit separate eESPDs. If a subcontractor's value exceeds 10% of the contract value, they must also comply with Regulation (EU) No 833/2014. The Prime Contractor is responsible for all services, regardless of subcontracting.
- Parent-company guarantee or bond requirements: Not specified.
9. Risks, red flags & unusuals
- Turnover requirement: The €1.8 million average annual turnover requirement is significantly higher than the estimated contract value of €900,000 over three years (€300,000 per year). This suggests a potential preference for larger, established providers or a need for bidders to demonstrate substantial capacity beyond this specific contract.
- Insurance levels: The required insurance coverages, particularly Public Liability (€6.5 million) and Cyber Security (€2.5 million), are substantial and may represent a significant cost for smaller providers.
- SME encouragement vs. turnover: While the Authority states a policy to encourage SME participation, the high turnover requirement could act as a barrier. Bidders are encouraged to form relationships, suggesting consortia may be a viable route for SMEs.
- Transition timeline: A managed service operational within 8 weeks of contract signing and full technical/service delivery within 3 months are tight deadlines, requiring a well-prepared transition plan.
- Foreign Subsidies Regulation: Tenderers must be aware of and comply with Regulation (EU) 2022/2560 on Foreign Subsidies, potentially requiring prior notification or declaration of foreign financial contributions.
10. SME fit assessment
This tender is structured to be challenging for very small businesses due to the significant turnover and insurance requirements. A credible bidder would likely be a medium-sized enterprise or a larger established provider with a dedicated cybersecurity division.
- Who can credibly bid: Companies with demonstrated experience in providing SOC, SIEM, and Managed IR services, possessing ISO 27001 certification, and capable of meeting the €1.8 million average annual turnover and high insurance thresholds.
- Consortium/sub-contracting: The tender explicitly encourages SMEs to explore forming relationships with other SMEs or larger enterprises. Subcontracting is permitted, and subcontractors must submit their own eESPDs. This indicates that a consortium approach is a viable strategy for SMEs to meet the requirements.
- Indicative bid-prep effort: Preparing a compliant bid, including the eESPD, detailed technical responses, pricing schedules, and declarations, would likely require 10-20 working days for a dedicated bid team.
- Pwin signal: The tender does not explicitly name an incumbent. However, the substantial turnover and insurance requirements, coupled with the specific technical demands of SOC/SIEM/IR, suggest that established players in the cybersecurity services market are likely to be the primary bidders. The encouragement of SME participation via consortia is a positive signal for smaller firms willing to collaborate.
11. Where to dig deeper
- Source RFT filename: HSA-services-request-for-tender-SIEMSOC.docx
- eTenders CFT ID: Not specified
- Contact email or clarification portal: Messaging facility on www.etenders.gov.ie
- Most important attachments:
- Appendix 1: Requirements and Specifications
- Appendix 2: Pricing Schedule
- Appendix 3: Tenderer’s Statement
Can you bid?
Required certifications
- ISO 27001
Minimum turnover
€1,800,000
Public liability insurance
€6,500,000
Professional indemnity insurance
€1,000,000
Named standards / methodologies
Scoring
Most Economically Advantageous Tender
Documents (3)
6_HSA_SOC_SIEM_IR_Pricing Schedule.xlsx
19.9 KB · Pricing / BOQ / Schedule of Rates
espdRequest-8939732.pdf
70.9 KB · ESPD (European Single Procurement Document)
HSA-services-request-for-tender-SIEMSOC.docx
218.4 KB
Original notice text
Procurement of a Security Operations Centre (SOC), Security Information and Event Management (SIEM) and Managed Incident Response 1(IR) Service
AI analysis updated 17 hours, 33 minutes ago
Value
€900k
Deadline
12 Oct
Location
Ireland
Procedure
Open
Clarification
22 Sep 2026
eTenders ID
8939732
Ask AI
Knows this tender's documents
Example only — sign up to ask about this tender