Skip to content
TenderMatch
← Tenders / SOC, SIEM and Managed IR Service for Health and Safety Authority
Open IT & Software Services Open

SOC, SIEM and Managed IR Service for Health and Safety Authority

Value

€900k

Deadline

12 Oct

Procurement for a Security Operations Centre (SOC), Security Information and Event Management (SIEM), and Managed Incident Response (IR) service for the Health and Safety Authority.

SME fit: Medium Bid effort: Medium

HSA seeks SOC, SIEM, and Managed IR services for €900,000 over 36 months

Bidder profile

This tender is suitable for established cybersecurity service providers with significant experience in SOC, SIEM, and Managed IR, capable of meeting high turnover and insurance requirements. SMEs may participate via consortia or subcontracting.

Risks & flags

  • High turnover requirement relative to contract value
  • Substantial insurance requirements
  • Tight transition timeline
  • Potential barrier for SMEs despite encouragement

Briefing

AI-generated analysis of the documents. Check the official notice and any amendments for current submission details.

1. At a glance

Buyer Health and Safety Authority
Title SOC, SIEM and Managed IR Service
CPV / category Not specified
Estimated value €900,000
Per-year (if multi-year) €300,000
Procedure type Open procedure
Lots Not specified
Location Ireland
Contract length 36 months
Submission deadline 2026-10-12 16:00
Go-live / start Not specified

2. Scope of Work

The Health and Safety Authority (HSA) requires a Security Operations Centre (SOC), Security Information and Event Management (SIEM), and Managed Incident Response (IR) service. The estimated expenditure for these services over the contract term, including potential extensions, is €900,000 (excluding VAT). The contract duration is 36 months, with an option for up to two extensions of 12 months each.

The core components of the required service include:

  • Security Operations Centre (SOC): This involves the continuous monitoring of the Authority's IT infrastructure and security systems. The SOC will be responsible for detecting, analysing, and responding to security threats and incidents in real-time.
  • Security Information and Event Management (SIEM): A SIEM system is required to collect, aggregate, and analyse security logs and event data from various sources across the Authority's network. This will enable threat detection, compliance reporting, and forensic analysis. The service must include User and Entity Behaviour Analysis (UEBA) capabilities.
  • Managed Incident Response (IR): This component covers the end-to-end management of security incidents. It includes investigation, containment, eradication, and recovery from security breaches. The service must provide detailed reporting, including Root Cause Analysis, for a minimum of 6 months and a maximum of 12 months post-incident, with log file retention for a specified period.
  • Threat Intelligence and Hunting: Proactive threat hunting and the integration of threat intelligence feeds are required to identify and mitigate emerging threats before they impact the Authority's systems.
  • Reporting: Regular reporting is mandated, including monthly, quarterly, and annual review meetings. Specific reporting requirements for incidents and overall security posture will be detailed.
  • Transition: A managed service operational within 8 weeks of contract signing is required. Technical and service requirements must be delivered within 3 months of contract signing.
  • Resilience and Compliance: The service must ensure Disaster Recovery (DR) resilience and compliance with relevant regulations.

The service provider will be expected to manage the SIEM platform and provide the SOC and IR functions. The Authority seeks a comprehensive solution to enhance its cybersecurity posture.

3. Background & buyer context

This procurement is initiated by the Health and Safety Authority (HSA) to establish a Security Operations Centre (SOC), Security Information and Event Management (SIEM), and Managed Incident Response (IR) service. The estimated value of the contract is €900,000 over an initial 36-month term, with potential for extensions. The HSA is seeking to enhance its cybersecurity capabilities and ensure the protection of its IT infrastructure and data. The procurement is being conducted under an open procedure, indicating a desire to attract a broad range of potential suppliers. The Authority's policy encourages participation by Small and Medium Enterprises (SMEs), suggesting a willingness to consider consortia or subcontracting arrangements to facilitate SME involvement.

4. Eligibility & selection criteria

Bidders must meet the following criteria to be considered:

  • Turnover requirement:
  • Average annual turnover of €1,800,000 for the last 3 financial years, confirmed by an auditor/accountant's statement.
  • Insurance:
  • Employer’s Liability: €13 million
  • Public Liability: €6.5 million
  • Product Liability: €6.5 million
  • Professional Indemnity: €1 million
  • Cyber Security: €2.5 million
  • Certifications:
  • ISO 27001 certification for SOC SIEM Managed Service, issued by an appropriately accredited body.
  • Past experience:
  • Not specified for this tender.
  • Personnel:
  • Not specified for this tender.
  • Geographic / facility constraints:
  • Technical and service requirements delivered/in place within 3 months of contract signing.
  • Insurance policies must include Ireland within their territorial limits and jurisdiction.

5. Award criteria & scoring

The contract will be awarded based on the most economically advantageous tender, determined by a combination of cost and qualitative criteria. The total score is 10,000 points, with Cost accounting for 3,000 points and Qualitative Criteria for 7,000 points.

Award Criteria Weight (%) Sub-criteria Minimum Score Required
Cost (A) 3,000 Lowest cost receives maximum score -
Qualitative (Total) 7,000 3,500
Technical (B) 2,000 SIEM (B1: 1250), Threat Intel (B2: 500), Reporting (B3: 250) 1,000
Services (C) 4,000 Experience (C1: 150), SOC (C2: 1500), Incident Mgmt (C3: 500), Incident Response (C4: 1000), DR/Compliance (C5: 850) 2,000
Transition (D) 1,000 Transition plan 500

The lowest cost tender that meets all minimum qualitative requirements receives the maximum cost score.

6. Submission requirements

Bidders must submit the following:

  • European Single Procurement Document (eESPD): Electronic version, confirming compliance with exclusion grounds and selection criteria.
  • Method statement / response document: Not specified by template or page limit.
  • CVs: Not specified.
  • Pricing schedule: Appendix 2, all-inclusive Euro prices, exclusive of VAT. Prices must remain valid for 6 months from the tender deadline.
  • Case studies: Not specified.
  • Declarations:
  • Tenderer’s Statement (Appendix 3), signed on letterhead.
  • Declaration as to Personal Circumstances (Appendix 4).
  • Tax Clearance Access Number and Tax Reference Number for online verification.
  • Conflict of Interest declaration.
  • Mandatory site visit: Not specified.
  • Submission portal: www.etenders.gov.ie electronic tenderbox. File size limit 250MB per file, 2GB total. Tenders must be in English.

7. Key dates & process

Event Date / Time
RFT issued 28/08/2026
Clarification deadline 22/09/2026 17:00
Mandatory site visit Not specified
Tender deadline 12/10/2026 17:00
Expected award Not specified
Contract start Not specified
Go-live / mobilisation Not specified

8. Contract terms that matter

  • Term: 36 months, with an option for up to two 12-month extensions.
  • Payment terms: Subject to the Services Contract (Appendix 5). Invoices are deemed accepted if no queries are raised within 14 days.
  • Key SLAs/KPIs: Not detailed in the provided extract, but implied through the award criteria for SOC, Incident Management, and Incident Response.
  • Liquidated damages or penalty regimes: Not specified.
  • Termination clauses: Either party may terminate with 14 days' notice in certain circumstances. Breach remediation is allowed within 30 days of a written request.
  • IP ownership: Not specified.
  • Sub-contracting rules: Subcontractors must submit separate eESPDs. If a subcontractor's value exceeds 10% of the contract value, they must also comply with Regulation (EU) No 833/2014. The Prime Contractor is responsible for all services, regardless of subcontracting.
  • Parent-company guarantee or bond requirements: Not specified.

9. Risks, red flags & unusuals

  • Turnover requirement: The €1.8 million average annual turnover requirement is significantly higher than the estimated contract value of €900,000 over three years (€300,000 per year). This suggests a potential preference for larger, established providers or a need for bidders to demonstrate substantial capacity beyond this specific contract.
  • Insurance levels: The required insurance coverages, particularly Public Liability (€6.5 million) and Cyber Security (€2.5 million), are substantial and may represent a significant cost for smaller providers.
  • SME encouragement vs. turnover: While the Authority states a policy to encourage SME participation, the high turnover requirement could act as a barrier. Bidders are encouraged to form relationships, suggesting consortia may be a viable route for SMEs.
  • Transition timeline: A managed service operational within 8 weeks of contract signing and full technical/service delivery within 3 months are tight deadlines, requiring a well-prepared transition plan.
  • Foreign Subsidies Regulation: Tenderers must be aware of and comply with Regulation (EU) 2022/2560 on Foreign Subsidies, potentially requiring prior notification or declaration of foreign financial contributions.

10. SME fit assessment

This tender is structured to be challenging for very small businesses due to the significant turnover and insurance requirements. A credible bidder would likely be a medium-sized enterprise or a larger established provider with a dedicated cybersecurity division.

  • Who can credibly bid: Companies with demonstrated experience in providing SOC, SIEM, and Managed IR services, possessing ISO 27001 certification, and capable of meeting the €1.8 million average annual turnover and high insurance thresholds.
  • Consortium/sub-contracting: The tender explicitly encourages SMEs to explore forming relationships with other SMEs or larger enterprises. Subcontracting is permitted, and subcontractors must submit their own eESPDs. This indicates that a consortium approach is a viable strategy for SMEs to meet the requirements.
  • Indicative bid-prep effort: Preparing a compliant bid, including the eESPD, detailed technical responses, pricing schedules, and declarations, would likely require 10-20 working days for a dedicated bid team.
  • Pwin signal: The tender does not explicitly name an incumbent. However, the substantial turnover and insurance requirements, coupled with the specific technical demands of SOC/SIEM/IR, suggest that established players in the cybersecurity services market are likely to be the primary bidders. The encouragement of SME participation via consortia is a positive signal for smaller firms willing to collaborate.

11. Where to dig deeper

  • Source RFT filename: HSA-services-request-for-tender-SIEMSOC.docx
  • eTenders CFT ID: Not specified
  • Contact email or clarification portal: Messaging facility on www.etenders.gov.ie
  • Most important attachments:
  • Appendix 1: Requirements and Specifications
  • Appendix 2: Pricing Schedule
  • Appendix 3: Tenderer’s Statement
until submission deadline — 12 Oct 2026 at 17:00 Deadline passed

Can you bid?

Required certifications

  • ISO 27001

Minimum turnover

€1,800,000

Public liability insurance

€6,500,000

Professional indemnity insurance

€1,000,000

Named standards / methodologies

ISO 27001

Scoring

Most Economically Advantageous Tender

Documents (3)

XLSX

6_HSA_SOC_SIEM_IR_Pricing Schedule.xlsx

19.9 KB · Pricing / BOQ / Schedule of Rates

PDF

espdRequest-8939732.pdf

70.9 KB · ESPD (European Single Procurement Document)

DOCX

HSA-services-request-for-tender-SIEMSOC.docx

218.4 KB

Original notice text

Procurement of a Security Operations Centre (SOC), Security Information and Event Management (SIEM) and Managed Incident Response 1(IR) Service

AI analysis updated 17 hours, 33 minutes ago

Bid ↗
Details

Value

€900k

Deadline

12 Oct

View on eTenders ↗

Location

Ireland

Procedure

Open

Clarification

22 Sep 2026

eTenders ID

8939732

✦ Ask AI about this tender

Ask AI

Knows this tender's documents

Is this a good fit for us?
Based on the deadline, buyer, and eligibility requirements in the tender documents, here's a quick read on fit — with citations back to the exact clause 1 so you can verify it yourself.

Example only — sign up to ask about this tender