Skip to content
TenderMatch
The recorded submission deadline has passed. Find open opportunities. Check the official notice for amendments.
← Tenders / Single Party Framework for a 24 / 7 SOC, with SIEM, XDR and associated services
Closed IT & Software Services SME Suitable Framework Open

Single Party Framework for a 24 / 7 SOC, with SIEM, XDR and associated services

Value

€1.8m

Deadline

12 Jun

Framework for 24/7 SOC with SIEM and XDR services for Pobal

SME fit: Medium Bid effort: Medium 📍 Dublin

Framework for 24/7 SOC with SIEM and XDR services for Pobal

Bidder profile

Suitable for firms with significant experience in managed security services and ISO/IEC 27001 certification.

Risks & flags

  • High insurance requirements
  • Data residency within EEA
  • Transition from incumbent provider

Briefing

AI-generated analysis of the documents. Check the official notice and any amendments for current submission details.

1. At a glance

Buyer Pobal
Title Single Party Framework for a 24 / 7 SOC, with SIEM, XDR and associated services
CPV / category Not stated
Estimated value €1.8 million
Per-year Not disclosed
Procedure type Single-party framework
Lots None
Location Dublin, Ireland
Contract length 4 years
Submission deadline 2026-06-05 11:00:00
Go-live / start Start of Q3 2026

2. Scope of Work

The tender seeks a contractor to establish a single-party framework for a fully managed 24x7x365 Security Operations Centre (SOC) with Security Information and Event Management (SIEM), Extended Detection and Response (XDR) services, and associated services. The framework aims to provide end-to-end security monitoring and incident response for Pobal's ICT infrastructure.

  • 24x7 SOC Operations: Continuous monitoring, triage, and incident response for SIEM, XDR, EDR, identity, email, cloud, and network telemetry.
  • Managed SIEM: Onboarding and normalisation of log sources, capacity planning, retention management, and cost optimisation.
  • Managed XDR: Multi-tenant configuration, hardening, onboarding, and continuous management of XDR platforms (e.g., Microsoft Defender XDR).
  • Detection Engineering: Development and tuning of SIEM rules, playbooks, and SOAR automation for rapid response.
  • Data Collection & Integration: Ingest and correlate security logs from cloud platforms, networks, servers, endpoints, and relevant business systems.
  • Threat Hunting: Regular proactive hunts aligned to MITRE ATT&CK, with documented findings and detection improvements.
  • Automated Response: Implement and maintain automation and orchestration playbooks for common security scenarios.
  • Incident Response: 24x7 containment guidance, remote forensics, root cause analysis, and post-incident reporting.
  • Governance & Reporting: Monthly service reviews, quarterly executive reports, KPIs (MTTD, MTTR), and annual assurance exercises.
  • Compliance & Retention: Retain security logs in accordance with regulatory and organisational requirements.
  • Transition/Onboarding Services: Structured transition (maximum 4 weeks) to ensure continuity of service with no degradation of security monitoring or incident response capability.

3. Background & buyer context

Pobal, acting on behalf of the Irish Government, supports communities and local agencies in achieving social inclusion and development. This procurement aligns with Pobal's strategic aim to enhance its ICT infrastructure's security and resilience. The current framework consolidates ICT support services into a single agile framework to facilitate dynamic expansion and efficient management. The incumbent provider delivers managed SIEM, SOC, and XDR services. This tender represents a competitive process to appoint a new service provider, ensuring uninterrupted security monitoring and incident response capabilities.

4. Eligibility & selection criteria

  • Turnover requirement: Not specified for this tender.
  • Insurance:
  • Employer’s Liability: €13 million
  • Public Liability: €6.5 million
  • Product Liability: €6.5 million
  • Professional Indemnity: €1.5 million
  • Cyber Insurance: €2 million
  • Certifications: ISO/IEC 27001 certification (or demonstrable equivalent).
  • Past experience: Not specified for this tender.
  • Personnel: Not specified for this tender.
  • Geographic / facility constraints: Data must be hosted and processed within the European Economic Area (EEA).

5. Award criteria & scoring

Criterion Weight (%) Sub-criteria Pass/fail thresholds
Service delivery methodology 35% Understanding of requirements, proposed methodology Minimum marks: 1,750
Management of services 10% Service management approach Minimum marks: 500
Proposed team 15% Team details Minimum marks: 750

The price/quality split follows the MEAT (Most Economically Advantageous Tender) principle.

6. Submission requirements

  • Method statement / response document: Use named template, no page limits specified.
  • CVs: Required for SOC Lead and L3 SOC Analyst roles, page count not specified.
  • Pricing schedule: Use provided Excel template.
  • Case studies: Not specified.
  • Declarations: ESPD, Bona Fides, Tax clearance, Conflict of Interest.
  • Mandatory site visit: Not specified.
  • Submission portal: eTenders, specific format rules not detailed.

7. Key dates & process

Event Date
RFT issued Not specified
Clarification deadline Not specified
Tender deadline 2026-06-05 11:00:00
Expected award June/July 2026
Contract start Start of Q3 2026
Go-live / mobilisation Not specified

8. Contract terms that matter

The framework agreement is for a maximum of four years, subject to annual performance reviews. The initial call-off contract is two years, with possible extensions of two additional twelve-month periods. Payment terms are not specified. Key SLAs include 24x7 monitoring and response capabilities. Termination clauses allow for contract award to the next highest scoring tenderer if the framework member cannot deliver. Intellectual property ownership, sub-contracting rules, and parent-company guarantee requirements are not specified.

9. Risks, red flags & unusuals

The tender requires a high level of insurance coverage, which may limit participation to larger firms. The geographic constraint of data residency within the EEA could restrict non-EU bidders. The framework's maximum spend of €1.8 million is indicative, with no guaranteed expenditure. The transition requirement from the incumbent provider could pose risks for new entrants, necessitating a detailed transition plan.

10. SME fit assessment

This tender is suitable for firms with significant experience in managed security services, particularly those with ISO/IEC 27001 certification. The high insurance requirements suggest that larger SMEs or those in consortiums may be more viable. Consortium or sub-contracting is allowed, with the requirement to establish legal personality if successful. Bid preparation effort is moderate, with a detailed response document and pricing schedule required. The presence of an incumbent provider may influence the probability of winning for new entrants.

11. Where to dig deeper

  • Source RFT filename: Pobal 0395 ICT Managed XDR (Extended Detection and Response) Services RFT.pdf
  • Contact email or clarification portal: Not specified
  • Important attachments:
  • "Appendix B2 — Suitability Assessment"
  • "Mandatory Requirements Schedule"

Can you bid?

Required certifications

  • ISO/IEC 27001

Public liability insurance

€6,500,000

Professional indemnity insurance

€1,500,000

Scoring

Most Economically Advantageous Tender

Documents (9)

PDF

Pobal 0395 ICT Managed XDR (Extended Detection and Response) Services RFT.pdf

639.0 KB · RFT / Invitation to Tender

XLSX

Pobal 0395 XDR Services Appendix 3 - Pricing Schedule.xlsx

58.7 KB · Pricing / BOQ / Schedule of Rates

DOCX

Pobal 0395 XDR Services Appendix 1 - Sample Framework Agreement.docx

342.9 KB · Contract / Agreement / Terms

DOCX

Pobal 0395 XDR Services Appendix 5 - Non-Disclosure Agreement.docx

14.3 KB · Contract / Agreement / Terms

PDF

0395 Pobal XDR Clarification #1.pdf

119.5 KB · Clarification / Addendum

PDF

0395 Pobal XDR Clarification #2.pdf

168.5 KB · Clarification / Addendum

PDF

0395 Pobal XDR Clarification #3.pdf

242.7 KB · Clarification / Addendum

PDF

0395 Pobal XDR Clarification #4.pdf

265.1 KB · Clarification / Addendum

DOCX

Pobal 0395 XDR Services Appendix 2 - TRD.docx

339.4 KB · Appendix / Annex

Original notice text

The Contracting Authority ICT infrastructure is a closely integrated ecosystem setup uniquely to fulfil operational requirements. In recent years, as part of ongoing growth, the Contracting Authority ICT infrastructure support service was consolidated into a single agile Framework Agreement, so that expansion could be dynamic and easily managed through a single supplier with flexibility, and staffing resources in mind. While Contracting Authority ICT staff are trained and skilled in most of the existing product ranges in use, the external support provided via the existing Framework is part of a vital component to ensure the efficient running of day-to-day operations within Contracting Authority. The Framework covers working with Contracting Authority ICT, and other key ICT vendors/ suppliers in commissioning the services. The tender must demonstrate this experience in working with in these types of scenarios and set out the platform accordingly. A key requirement of the Framework is the tenderer’s ability to design, supply, commission and fully support, with 24 hour monitoring all security elements and requirements relating such as for example firewalls, servers, hosts, logs, switches, Active Directory/Entra within Contracting Authority's current and future technical stack and are located both on-premise, and cloud/hybrid environment within the Contracting Authority Data Centres, which reside in two Government Data centres in the Dublin region (Ireland) (accessed via Government Network (GN) connection), and Microsoft Azure space (EU). The infrastructure comprises more than 400 Windows servers, ten Fortinet firewalls and WAFs, and approximately 100,000 Active Directory/Entra B2B and B2C customer users, hosted across five domains utilising on-premises, hybrid, and cloud solutions such as Microsoft 365, Microsoft Dynamics 365, SharePoint, and Power Platform. The Contracting Authority infrastructure is categorised in Gold, Silver and Bronze categories based on the data / information security risk profile – only Gold categorised infrastructure is in scope for this Framework.

AI analysis updated 2 months, 2 weeks ago

Bid ↗
Details

Value

€1.8m

Deadline

12 Jun

View on eTenders ↗

Buyer

Pobal

Location

Dublin, Ireland

Procedure

Open

eTenders ID

8029941

✦ Ask AI about this tender

Ask AI

Knows this tender's documents

Is this a good fit for us?
Based on the deadline, buyer, and eligibility requirements in the tender documents, here's a quick read on fit — with citations back to the exact clause 1 so you can verify it yourself.

Example only — sign up to ask about this tender