Single Party Framework for a 24 / 7 SOC, with SIEM, XDR and associated services
Value
€1.8m
Deadline
12 Jun
12 Jun 2026
Value
€1.8m
Deadline
12 Jun
Framework for 24/7 SOC with SIEM and XDR services for Pobal
Framework for 24/7 SOC with SIEM and XDR services for Pobal
Bidder profile
Suitable for firms with significant experience in managed security services and ISO/IEC 27001 certification.
Risks & flags
- High insurance requirements
- Data residency within EEA
- Transition from incumbent provider
Briefing
AI-generated analysis of the documents. Check the official notice and any amendments for current submission details.
1. At a glance
| Buyer | Pobal |
|---|---|
| Title | Single Party Framework for a 24 / 7 SOC, with SIEM, XDR and associated services |
| CPV / category | Not stated |
| Estimated value | €1.8 million |
| Per-year | Not disclosed |
| Procedure type | Single-party framework |
| Lots | None |
| Location | Dublin, Ireland |
| Contract length | 4 years |
| Submission deadline | 2026-06-05 11:00:00 |
| Go-live / start | Start of Q3 2026 |
2. Scope of Work
The tender seeks a contractor to establish a single-party framework for a fully managed 24x7x365 Security Operations Centre (SOC) with Security Information and Event Management (SIEM), Extended Detection and Response (XDR) services, and associated services. The framework aims to provide end-to-end security monitoring and incident response for Pobal's ICT infrastructure.
- 24x7 SOC Operations: Continuous monitoring, triage, and incident response for SIEM, XDR, EDR, identity, email, cloud, and network telemetry.
- Managed SIEM: Onboarding and normalisation of log sources, capacity planning, retention management, and cost optimisation.
- Managed XDR: Multi-tenant configuration, hardening, onboarding, and continuous management of XDR platforms (e.g., Microsoft Defender XDR).
- Detection Engineering: Development and tuning of SIEM rules, playbooks, and SOAR automation for rapid response.
- Data Collection & Integration: Ingest and correlate security logs from cloud platforms, networks, servers, endpoints, and relevant business systems.
- Threat Hunting: Regular proactive hunts aligned to MITRE ATT&CK, with documented findings and detection improvements.
- Automated Response: Implement and maintain automation and orchestration playbooks for common security scenarios.
- Incident Response: 24x7 containment guidance, remote forensics, root cause analysis, and post-incident reporting.
- Governance & Reporting: Monthly service reviews, quarterly executive reports, KPIs (MTTD, MTTR), and annual assurance exercises.
- Compliance & Retention: Retain security logs in accordance with regulatory and organisational requirements.
- Transition/Onboarding Services: Structured transition (maximum 4 weeks) to ensure continuity of service with no degradation of security monitoring or incident response capability.
3. Background & buyer context
Pobal, acting on behalf of the Irish Government, supports communities and local agencies in achieving social inclusion and development. This procurement aligns with Pobal's strategic aim to enhance its ICT infrastructure's security and resilience. The current framework consolidates ICT support services into a single agile framework to facilitate dynamic expansion and efficient management. The incumbent provider delivers managed SIEM, SOC, and XDR services. This tender represents a competitive process to appoint a new service provider, ensuring uninterrupted security monitoring and incident response capabilities.
4. Eligibility & selection criteria
- Turnover requirement: Not specified for this tender.
- Insurance:
- Employer’s Liability: €13 million
- Public Liability: €6.5 million
- Product Liability: €6.5 million
- Professional Indemnity: €1.5 million
- Cyber Insurance: €2 million
- Certifications: ISO/IEC 27001 certification (or demonstrable equivalent).
- Past experience: Not specified for this tender.
- Personnel: Not specified for this tender.
- Geographic / facility constraints: Data must be hosted and processed within the European Economic Area (EEA).
5. Award criteria & scoring
| Criterion | Weight (%) | Sub-criteria | Pass/fail thresholds |
|---|---|---|---|
| Service delivery methodology | 35% | Understanding of requirements, proposed methodology | Minimum marks: 1,750 |
| Management of services | 10% | Service management approach | Minimum marks: 500 |
| Proposed team | 15% | Team details | Minimum marks: 750 |
The price/quality split follows the MEAT (Most Economically Advantageous Tender) principle.
6. Submission requirements
- Method statement / response document: Use named template, no page limits specified.
- CVs: Required for SOC Lead and L3 SOC Analyst roles, page count not specified.
- Pricing schedule: Use provided Excel template.
- Case studies: Not specified.
- Declarations: ESPD, Bona Fides, Tax clearance, Conflict of Interest.
- Mandatory site visit: Not specified.
- Submission portal: eTenders, specific format rules not detailed.
7. Key dates & process
| Event | Date |
|---|---|
| RFT issued | Not specified |
| Clarification deadline | Not specified |
| Tender deadline | 2026-06-05 11:00:00 |
| Expected award | June/July 2026 |
| Contract start | Start of Q3 2026 |
| Go-live / mobilisation | Not specified |
8. Contract terms that matter
The framework agreement is for a maximum of four years, subject to annual performance reviews. The initial call-off contract is two years, with possible extensions of two additional twelve-month periods. Payment terms are not specified. Key SLAs include 24x7 monitoring and response capabilities. Termination clauses allow for contract award to the next highest scoring tenderer if the framework member cannot deliver. Intellectual property ownership, sub-contracting rules, and parent-company guarantee requirements are not specified.
9. Risks, red flags & unusuals
The tender requires a high level of insurance coverage, which may limit participation to larger firms. The geographic constraint of data residency within the EEA could restrict non-EU bidders. The framework's maximum spend of €1.8 million is indicative, with no guaranteed expenditure. The transition requirement from the incumbent provider could pose risks for new entrants, necessitating a detailed transition plan.
10. SME fit assessment
This tender is suitable for firms with significant experience in managed security services, particularly those with ISO/IEC 27001 certification. The high insurance requirements suggest that larger SMEs or those in consortiums may be more viable. Consortium or sub-contracting is allowed, with the requirement to establish legal personality if successful. Bid preparation effort is moderate, with a detailed response document and pricing schedule required. The presence of an incumbent provider may influence the probability of winning for new entrants.
11. Where to dig deeper
- Source RFT filename: Pobal 0395 ICT Managed XDR (Extended Detection and Response) Services RFT.pdf
- Contact email or clarification portal: Not specified
- Important attachments:
- "Appendix B2 — Suitability Assessment"
- "Mandatory Requirements Schedule"
Can you bid?
Required certifications
- ISO/IEC 27001
Public liability insurance
€6,500,000
Professional indemnity insurance
€1,500,000
Scoring
Most Economically Advantageous Tender
Documents (9)
Pobal 0395 ICT Managed XDR (Extended Detection and Response) Services RFT.pdf
639.0 KB · RFT / Invitation to Tender
Pobal 0395 XDR Services Appendix 3 - Pricing Schedule.xlsx
58.7 KB · Pricing / BOQ / Schedule of Rates
Pobal 0395 XDR Services Appendix 1 - Sample Framework Agreement.docx
342.9 KB · Contract / Agreement / Terms
Pobal 0395 XDR Services Appendix 5 - Non-Disclosure Agreement.docx
14.3 KB · Contract / Agreement / Terms
0395 Pobal XDR Clarification #1.pdf
119.5 KB · Clarification / Addendum
0395 Pobal XDR Clarification #2.pdf
168.5 KB · Clarification / Addendum
0395 Pobal XDR Clarification #3.pdf
242.7 KB · Clarification / Addendum
0395 Pobal XDR Clarification #4.pdf
265.1 KB · Clarification / Addendum
Pobal 0395 XDR Services Appendix 2 - TRD.docx
339.4 KB · Appendix / Annex
Original notice text
The Contracting Authority ICT infrastructure is a closely integrated ecosystem setup uniquely to fulfil operational requirements. In recent years, as part of ongoing growth, the Contracting Authority ICT infrastructure support service was consolidated into a single agile Framework Agreement, so that expansion could be dynamic and easily managed through a single supplier with flexibility, and staffing resources in mind. While Contracting Authority ICT staff are trained and skilled in most of the existing product ranges in use, the external support provided via the existing Framework is part of a vital component to ensure the efficient running of day-to-day operations within Contracting Authority. The Framework covers working with Contracting Authority ICT, and other key ICT vendors/ suppliers in commissioning the services. The tender must demonstrate this experience in working with in these types of scenarios and set out the platform accordingly. A key requirement of the Framework is the tenderer’s ability to design, supply, commission and fully support, with 24 hour monitoring all security elements and requirements relating such as for example firewalls, servers, hosts, logs, switches, Active Directory/Entra within Contracting Authority's current and future technical stack and are located both on-premise, and cloud/hybrid environment within the Contracting Authority Data Centres, which reside in two Government Data centres in the Dublin region (Ireland) (accessed via Government Network (GN) connection), and Microsoft Azure space (EU). The infrastructure comprises more than 400 Windows servers, ten Fortinet firewalls and WAFs, and approximately 100,000 Active Directory/Entra B2B and B2C customer users, hosted across five domains utilising on-premises, hybrid, and cloud solutions such as Microsoft 365, Microsoft Dynamics 365, SharePoint, and Power Platform. The Contracting Authority infrastructure is categorised in Gold, Silver and Bronze categories based on the data / information security risk profile – only Gold categorised infrastructure is in scope for this Framework.
AI analysis updated 2 months, 2 weeks ago
Ask AI
Knows this tender's documents
Example only — sign up to ask about this tender