Cyber Security Consultancy and Technical Services
Value
€1.4m
Deadline
27 Aug
27 Aug 2026
Value
€1.4m
Deadline
27 Aug
Provision of cyber security consultancy and technical services to enhance compliance and resilience for the Department of Children, Disability and Equality.
Cyber security consultancy and technical services for the Department of Children, Disability and Equality
Bidder profile
Firms with experience in cyber security consultancy and compliance, capable of meeting insurance and turnover requirements.
Risks & flags
- High turnover requirement
- Regulatory compliance focus
- Absence of specified SLAs/KPIs
Briefing
AI-generated analysis of the documents. Check the official notice and any amendments for current submission details.
1. At a glance
| Buyer | Department of Children Disability and Equality |
|---|---|
| Title | Cyber Security Consultancy and Technical Services |
| CPV / category | not stated |
| Estimated value | €1,400,000 |
| Per-year (if multi-year) | not stated |
| Procedure type | Open procedure |
| Lots | not stated |
| Location | not stated |
| Contract length | 24 months, with up to 2 extensions of 12 months each |
| Submission deadline | 27 August 2026, 14:00 |
| Go-live / start | not stated |
2. Scope of Work
The contract involves the provision of comprehensive cyber security consultancy and technical services to the Department of Children, Disability and Equality (DCDE). The scope includes governance, compliance, and resilience support, as well as Managed Security Service Provider (MSSP) services. The contractor will assist the DCDE in closing gaps identified in the NIS2 readiness assessment, enhancing operational resilience, and ensuring compliance with various regulations, including NIS2, CER, and the National Cyber Security Bill 2024.
The work is structured into several key phases:
-
Initial Intensive Phase (8-9 months):
-
Focus on addressing remaining NIS2 readiness gaps.
-
Establishment of a combined compliance/resilience and MSSP operating model.
-
Ongoing Support:
-
Transition to a lighter-touch continuous improvement model.
-
Main operational focus on MSSP monitoring, emergency alert response, and ongoing assurance.
The MSSP services will include:
- Business-hours monitoring as a baseline.
- Emergency alert response outside business hours.
- Monitoring, triage, escalation, and remediation for security events affecting the DCDE environment, including systems such as Power Apps, Power Pages, Microsoft Fabric, SharePoint, and future Dynamics workloads.
Additionally, the contractor will be responsible for gathering and analyzing Cyber Threat Intelligence (CTI) from various sources to inform proactive security measures.
3. Background & buyer context
This procurement is initiated to enhance the cyber security posture of the Department of Children, Disability and Equality, particularly in light of increasing regulatory requirements and the need for improved resilience against cyber threats. The contract aligns with the government's broader strategy to bolster national cyber security frameworks, including compliance with the NIS2 directive and the forthcoming National Cyber Security Bill 2024. The DCDE has previously engaged in similar initiatives, but the current tender aims to address specific gaps identified in recent assessments.
4. Eligibility & selection criteria
Bidders must meet the following eligibility and selection criteria:
- Turnover requirement: Minimum average annual turnover of €700,000 excluding VAT for the last three financial years.
- Insurance:
- Employer’s Liability: €12.7m limit for any one claim.
- Public Liability: €6.5m limit for any one claim.
- Professional Indemnity: €1m for any one claim.
- Cyber Liability: €1m for any one claim.
- Certifications: Relevant cyber security certifications, such as ISO 27001, CISSP, CISM, and others.
- Past experience: Evidence of at least N comparable projects of similar size and complexity within the last three years.
- Personnel: Key personnel must have relevant experience in cyber governance and compliance.
- Geographic / facility constraints: Not specified for this tender.
5. Award criteria & scoring
Bids will be evaluated based on the following criteria:
| Criterion | Weight (%) | Sub-criteria | Pass/Fail Thresholds |
|---|---|---|---|
| Price | 40 | Cost-effectiveness | Not specified |
| Quality | 60 | Technical capability, experience, and methodology | Not specified |
The overall evaluation will follow the Most Economically Advantageous Tender (MEAT) principle, focusing on the best price-quality ratio.
6. Submission requirements
Bidders must submit the following documentation:
- Method statement / response document: Follow the named template with a specified page limit.
- CVs: For key personnel, adhering to a specified page count.
- Pricing schedule: Must use the named template.
- Case studies: At least two, demonstrating relevant experience and within a specified value range.
- Declarations: Including ESPD, Bona Fides, Tax clearance, and Conflict of Interest.
- Mandatory site visit: Not specified for this tender.
- Submission portal: Tenders must be submitted via the eTenders platform, following specific format rules.
7. Key dates & process
| Key Date | Date |
|---|---|
| RFT issued | 28 July 2026 |
| Clarification deadline | 11 August 2026, 14:00 |
| Tender deadline | 27 August 2026, 14:00 |
| Expected award | Not specified |
| Contract start | Not specified |
| Go-live / mobilisation | Not specified |
8. Contract terms that matter
Key contract terms include:
- Term and extensions: Initial term of 24 months, with up to two extensions of 12 months each.
- Payment terms: Payments will be made in accordance with the Services Contract.
- Key SLAs/KPIs: Not specified, but will likely include response times for MSSP services.
- Liquidated damages: Not specified.
- Termination clauses: Include provisions for termination with notice.
- IP ownership: Not specified.
- Sub-contracting rules: Allowed, but the Prime Contractor must be designated.
9. Risks, red flags & unusuals
Potential concerns for bidders include:
- The turnover requirement of €700,000 may limit participation from smaller firms.
- The contract's focus on compliance with specific regulations (NIS2, CER) may favor incumbents with established relationships and experience in these areas.
- The absence of specified SLAs/KPIs could lead to ambiguity in performance expectations.
- The lack of a mandatory site visit may limit bidders' understanding of the operational environment.
10. SME fit assessment
Small and medium enterprises (SMEs) that can credibly bid should have:
- Relevant experience in cyber security consultancy and compliance.
- The capacity to meet the insurance and turnover requirements.
- The ability to form partnerships or consortiums if necessary.
- Estimated bid preparation effort is likely to be significant, requiring several days to compile the necessary documentation.
- The presence of established incumbents may signal a competitive landscape, but opportunities exist for SMEs with niche expertise.
11. Where to dig deeper
- Source RFT filename: Cyber Security Consultancy and Technical Services RFT.docx
- eTenders CFT ID: Not specified.
- Contact email or clarification portal: Queries must be directed via the messaging facility on www.etenders.gov.ie.
- Important attachments:
- Appendix 1 — Requirements and Specifications
- Appendix 2 — Pricing Schedule
- Appendix 3 — Tenderer’s Statement
Can you bid?
Required certifications
- ISO 27001
- CISSP
- CISM
Minimum turnover
€700,000
Public liability insurance
€6,500,000
Professional indemnity insurance
€1,000,000
Scoring
Most Economically Advantageous Tender
Documents (4)
Cyber Security Consultancy and Technical Services RFT.docx
160.2 KB · RFT / Invitation to Tender
Cyber Security Consultancy and Technical Services TRD.docx
193.5 KB
ESPD_REQUEST_8732511.docx
28.7 KB · ESPD (European Single Procurement Document)
espdRequest-8732511.pdf
70.9 KB · ESPD (European Single Procurement Document)
Original notice text
DCDE seeks to appoint a partner to assist in the planning, implementation, and assure a cohesive programme that closes all gaps to compliance, operationalises Irish Risk Management Measures (RMMs) and NIS2 (Network and Information Security Directive (EU) 2022/2555) Article 21 measures, aligns DCDE to CyFun (Cyber Fundamentals Framework), and establishes governance, processes, and reporting required by the National Cyber Security Bill 2024. The appointed partner will deliver a comprehensive program addressing areas such governance, business continuity, risk management, operational resilience, and technical uplift to achieve compliance with NIS2 (Network and Information Security Directive (EU) 2022/2555), CyFun (Cyber Fundamentals Framework), and the National Cyber Security Bill 2024. The scope would include but is not limited to implementing risk analysis frameworks, incident handling processes, business continuity and disaster recovery plans, AI system security reviews (Artificial Intelligence), SAAS security reviews (Software as a Service) and supply chain security measures as well tabletop exercises and pen test reviews. It will also cover system acquisition and maintenance controls, vulnerability management, and assisting DCDE with coordinated vulnerability disclosure.
AI analysis updated 3 weeks, 1 day ago
Value
€1.4m
Deadline
27 Aug
Location
Not specified.
Procedure
Open
Clarification
11 Aug 2026
eTenders ID
8732511
Ask AI
Knows this tender's documents
Example only — sign up to ask about this tender