Skip to content
TenderMatch
The recorded submission deadline has passed. Find open opportunities. Check the official notice for amendments.
← Tenders / Provision of One Time Passcode services via API
Closed IT & Software Services Open

Provision of One Time Passcode services via API

Value

€800k

Deadline

29 Jul

Procurement for a provider of One Time Passcode (OTP) handling services via API for Multi-Factor Authentication (MFA).

SME fit: Medium Bid effort: Medium

Provision of One Time Passcode (OTP) services via API for Multi-Factor Authentication

Bidder profile

This tender is suitable for IT service providers specializing in secure messaging solutions, API development, and telecommunications, with experience in multi-factor authentication and robust security protocols.

Risks & flags

  • Potential for extensions up to 5 years total
  • High insurance requirements
  • Minimum turnover requirement

Briefing

AI-generated analysis of the documents. Check the official notice and any amendments for current submission details.

1. At a glance

Buyer Title CPV / category Estimated value Per-year Procedure type Lots Location Contract length Submission deadline Go-live / start | :--------------------------------------- | :------------------------------------------ | :------------- | :-------------- | :------- | :--------------- | :----- | :------- | :-------------- | :------------------ | :-------------- | Department of Enterprise, Tourism and Employment Provision of One Time Passcode services via API Not stated €800,000 Not stated Open procedure Not stated Ireland 12 months 2026-07-15 12:00 Not stated

2. Scope of Work

The procurement seeks a provider for One Time Passcode (OTP) handling services delivered via an Application Programming Interface (API). This service is intended for Multi-Factor Authentication (MFA) purposes. The contract duration is for 12 months, with the possibility of up to four 12-month extensions. The estimated expenditure over the contract term, including potential extensions, is €800,000 (excluding VAT).

The core activities and requirements for the successful bidder include:

  • API Provision: Availability of a fully documented RESTful API (or equivalent) to enable automated message sending, delivery reporting, and status querying.
  • Messaging Functionality:
  • Number formatting and normalization.
  • Routing traffic appropriately based on number characteristics.
  • Support for delivery receipts (DLRs).
  • Message queuing, batching, error handling, and retry logic.
  • System Performance & Availability:
  • Minimum 99% overall system uptime/availability statistics for the preceding 12 months.
  • Infrastructure capacity to support high-volume message transmission during peak periods.
  • Interoperability: Compliance with telecommunications standards and interoperability with Irish and international mobile networks.
  • Platform Architecture: Description of the platform architecture, hosting environment, and data flow.
  • Security & Data Protection:
  • Compliance with the General Data Protection Regulation (GDPR) and relevant Irish data protection legislation.
  • Secure API authentication methods (e.g., OAuth2, API keys, IP restrictions).
  • Encryption of data in transit (TLS/SSL) and at rest.
  • Data retention, deletion, and logging policies.
  • Incident management and breach notification procedures.
  • Service Support:
  • Details of customer and technical support arrangements, such as 24/7 support and ticketing systems.
  • Proposed Service Level Agreements (SLAs) including response times, performance metrics, and escalation procedures.
  • Methods for monitoring service performance, availability, and delivery success rates.
  • Reporting capabilities and dashboards for the Contracting Authority.
  • Personnel: Information on key personnel, including their qualifications, professional experience in telecommunications, API development, or SMS gateway management, and their roles/responsibilities.
  • Certifications: Evidence of relevant certifications such as ISO 27001 (Information Security Management) and ISO 20000 (IT Service Management), or other telecommunications or security standards. These may be held by the Tenderer or their subcontractors.

3. Background & buyer context

This procurement is being conducted by the Department of Enterprise, Tourism and Employment. The service is required to enhance Multi-Factor Authentication (MFA) capabilities through the provision of One Time Passcode (OTP) services via API. The tender is being run under an open procedure, as defined by the European Union (Award of Public Authority Contracts) Regulations 2016. The Department's policy seeks to encourage participation by Small and Medium Enterprises (SMEs) on a fair and equal basis, encouraging larger enterprises to include SMEs in their proposals.

4. Eligibility & selection criteria

  • Turnover requirement: Tenderers must demonstrate a minimum average annual turnover of €1,500,000 in each of the years 2022, 2023, and 2024 (and 2025 if available). Audited accounts for these periods are the primary supporting documentation.
  • Insurance: The successful Tenderer must hold the following insurances for the term of the Services Contract:
  • Employer’s Liability: €13,000,000
  • Public Liability: €6,500,000
  • Product Liability: €6,500,000
  • Professional Indemnity: €1,300,000
  • Cyber Liability: €5,000,000
  • Certifications: Tenderers should supply evidence of relevant certifications, such as ISO 27001 (Information Security Management) and ISO 20000 (IT Service Management), or other telecommunications or security standards. These may be held by the Tenderer or their subcontractors. SOC 2 Type II is also mentioned as an equivalent.
  • Past experience: Tenderers must outline at least three (3) comparable contracts delivered within the last three (3) years. These contracts must involve OTP handling services via API or equivalent telecommunications messaging platforms. For each reference, details of the client organisation, services delivered (including volumes, API type, service features), contract value and duration, and contact details for verification are required.
  • Personnel: Tenderers shall provide information on key personnel, including their relevant qualifications, professional experience in telecommunications, API development, or SMS gateway management, and their roles and responsibilities within the project. Specific minimum years of experience are not stated.
  • Geographic / facility constraints: Not specified for this tender, beyond the requirement for insurance policies to include Ireland within their territorial limits and jurisdiction.

5. Award criteria & scoring

Category Weighting Specific Evaluation Criteria

Can you bid?

Required certifications

  • ISO 27001
  • ISO 20000
  • SOC 2 Type II

Minimum turnover

€1,500,000

Public liability insurance

€6,500,000

Professional indemnity insurance

€1,300,000

Named standards / methodologies

RESTful APIOAuth2TLS/SSLGDPRISO 27001ISO 20000SOC 2 Type II

Documents (2)

DOCX

OTP Services via API_2a.docx

185.5 KB · RFT / Invitation to Tender

DOCX

OTP Services via API_2.docx

185.3 KB

Original notice text

The Department (and it's offices and agencies) wish to procure the provision of various types of OTP services to be accessed via API

AI analysis updated 1 month, 2 weeks ago

Bid ↗
Details

Value

€800k

Deadline

29 Jul

View on eTenders ↗

Location

Ireland

Procedure

Open

Clarification

15 Jul 2026

eTenders ID

8524061

✦ Ask AI about this tender

Ask AI

Knows this tender's documents

Is this a good fit for us?
Based on the deadline, buyer, and eligibility requirements in the tender documents, here's a quick read on fit — with citations back to the exact clause 1 so you can verify it yourself.

Example only — sign up to ask about this tender