Skip to content
TenderMatch
The recorded submission deadline has passed. Find open opportunities. Check the official notice for amendments.
← Tenders / Cyber Security Consultancy and Technical Services
Closed IT & Software Services SME Suitable Open

Cyber Security Consultancy and Technical Services

Value

€1.4m

Deadline

27 Aug

Provision of cyber security consultancy and technical services to enhance compliance and resilience for the Department of Children, Disability and Equality.

SME fit: Medium Bid effort: Medium

Cyber security consultancy and technical services for the Department of Children, Disability and Equality

Bidder profile

Firms with experience in cyber security consultancy and compliance, capable of meeting insurance and turnover requirements.

Risks & flags

  • High turnover requirement
  • Regulatory compliance focus
  • Absence of specified SLAs/KPIs

Briefing

AI-generated analysis of the documents. Check the official notice and any amendments for current submission details.

1. At a glance

Buyer Department of Children Disability and Equality
Title Cyber Security Consultancy and Technical Services
CPV / category not stated
Estimated value €1,400,000
Per-year (if multi-year) not stated
Procedure type Open procedure
Lots not stated
Location not stated
Contract length 24 months, with up to 2 extensions of 12 months each
Submission deadline 27 August 2026, 14:00
Go-live / start not stated

2. Scope of Work

The contract involves the provision of comprehensive cyber security consultancy and technical services to the Department of Children, Disability and Equality (DCDE). The scope includes governance, compliance, and resilience support, as well as Managed Security Service Provider (MSSP) services. The contractor will assist the DCDE in closing gaps identified in the NIS2 readiness assessment, enhancing operational resilience, and ensuring compliance with various regulations, including NIS2, CER, and the National Cyber Security Bill 2024.

The work is structured into several key phases:

  • Initial Intensive Phase (8-9 months):

  • Focus on addressing remaining NIS2 readiness gaps.

  • Establishment of a combined compliance/resilience and MSSP operating model.

  • Ongoing Support:

  • Transition to a lighter-touch continuous improvement model.

  • Main operational focus on MSSP monitoring, emergency alert response, and ongoing assurance.

The MSSP services will include:

  • Business-hours monitoring as a baseline.
  • Emergency alert response outside business hours.
  • Monitoring, triage, escalation, and remediation for security events affecting the DCDE environment, including systems such as Power Apps, Power Pages, Microsoft Fabric, SharePoint, and future Dynamics workloads.

Additionally, the contractor will be responsible for gathering and analyzing Cyber Threat Intelligence (CTI) from various sources to inform proactive security measures.

3. Background & buyer context

This procurement is initiated to enhance the cyber security posture of the Department of Children, Disability and Equality, particularly in light of increasing regulatory requirements and the need for improved resilience against cyber threats. The contract aligns with the government's broader strategy to bolster national cyber security frameworks, including compliance with the NIS2 directive and the forthcoming National Cyber Security Bill 2024. The DCDE has previously engaged in similar initiatives, but the current tender aims to address specific gaps identified in recent assessments.

4. Eligibility & selection criteria

Bidders must meet the following eligibility and selection criteria:

  • Turnover requirement: Minimum average annual turnover of €700,000 excluding VAT for the last three financial years.
  • Insurance:
  • Employer’s Liability: €12.7m limit for any one claim.
  • Public Liability: €6.5m limit for any one claim.
  • Professional Indemnity: €1m for any one claim.
  • Cyber Liability: €1m for any one claim.
  • Certifications: Relevant cyber security certifications, such as ISO 27001, CISSP, CISM, and others.
  • Past experience: Evidence of at least N comparable projects of similar size and complexity within the last three years.
  • Personnel: Key personnel must have relevant experience in cyber governance and compliance.
  • Geographic / facility constraints: Not specified for this tender.

5. Award criteria & scoring

Bids will be evaluated based on the following criteria:

Criterion Weight (%) Sub-criteria Pass/Fail Thresholds
Price 40 Cost-effectiveness Not specified
Quality 60 Technical capability, experience, and methodology Not specified

The overall evaluation will follow the Most Economically Advantageous Tender (MEAT) principle, focusing on the best price-quality ratio.

6. Submission requirements

Bidders must submit the following documentation:

  • Method statement / response document: Follow the named template with a specified page limit.
  • CVs: For key personnel, adhering to a specified page count.
  • Pricing schedule: Must use the named template.
  • Case studies: At least two, demonstrating relevant experience and within a specified value range.
  • Declarations: Including ESPD, Bona Fides, Tax clearance, and Conflict of Interest.
  • Mandatory site visit: Not specified for this tender.
  • Submission portal: Tenders must be submitted via the eTenders platform, following specific format rules.

7. Key dates & process

Key Date Date
RFT issued 28 July 2026
Clarification deadline 11 August 2026, 14:00
Tender deadline 27 August 2026, 14:00
Expected award Not specified
Contract start Not specified
Go-live / mobilisation Not specified

8. Contract terms that matter

Key contract terms include:

  • Term and extensions: Initial term of 24 months, with up to two extensions of 12 months each.
  • Payment terms: Payments will be made in accordance with the Services Contract.
  • Key SLAs/KPIs: Not specified, but will likely include response times for MSSP services.
  • Liquidated damages: Not specified.
  • Termination clauses: Include provisions for termination with notice.
  • IP ownership: Not specified.
  • Sub-contracting rules: Allowed, but the Prime Contractor must be designated.

9. Risks, red flags & unusuals

Potential concerns for bidders include:

  • The turnover requirement of €700,000 may limit participation from smaller firms.
  • The contract's focus on compliance with specific regulations (NIS2, CER) may favor incumbents with established relationships and experience in these areas.
  • The absence of specified SLAs/KPIs could lead to ambiguity in performance expectations.
  • The lack of a mandatory site visit may limit bidders' understanding of the operational environment.

10. SME fit assessment

Small and medium enterprises (SMEs) that can credibly bid should have:

  • Relevant experience in cyber security consultancy and compliance.
  • The capacity to meet the insurance and turnover requirements.
  • The ability to form partnerships or consortiums if necessary.
  • Estimated bid preparation effort is likely to be significant, requiring several days to compile the necessary documentation.
  • The presence of established incumbents may signal a competitive landscape, but opportunities exist for SMEs with niche expertise.

11. Where to dig deeper

  • Source RFT filename: Cyber Security Consultancy and Technical Services RFT.docx
  • eTenders CFT ID: Not specified.
  • Contact email or clarification portal: Queries must be directed via the messaging facility on www.etenders.gov.ie.
  • Important attachments:
  • Appendix 1 — Requirements and Specifications
  • Appendix 2 — Pricing Schedule
  • Appendix 3 — Tenderer’s Statement

Can you bid?

Required certifications

  • ISO 27001
  • CISSP
  • CISM

Minimum turnover

€700,000

Public liability insurance

€6,500,000

Professional indemnity insurance

€1,000,000

Scoring

Most Economically Advantageous Tender

Documents (4)

DOCX

Cyber Security Consultancy and Technical Services RFT.docx

160.2 KB · RFT / Invitation to Tender

DOCX

Cyber Security Consultancy and Technical Services TRD.docx

193.5 KB

DOCX

ESPD_REQUEST_8732511.docx

28.7 KB · ESPD (European Single Procurement Document)

PDF

espdRequest-8732511.pdf

70.9 KB · ESPD (European Single Procurement Document)

Original notice text

DCDE seeks to appoint a partner to assist in the planning, implementation, and assure a cohesive programme that closes all gaps to compliance, operationalises Irish Risk Management Measures (RMMs) and NIS2 (Network and Information Security Directive (EU) 2022/2555) Article 21 measures, aligns DCDE to CyFun (Cyber Fundamentals Framework), and establishes governance, processes, and reporting required by the National Cyber Security Bill 2024. The appointed partner will deliver a comprehensive program addressing areas such governance, business continuity, risk management, operational resilience, and technical uplift to achieve compliance with NIS2 (Network and Information Security Directive (EU) 2022/2555), CyFun (Cyber Fundamentals Framework), and the National Cyber Security Bill 2024. The scope would include but is not limited to implementing risk analysis frameworks, incident handling processes, business continuity and disaster recovery plans, AI system security reviews (Artificial Intelligence), SAAS security reviews (Software as a Service) and supply chain security measures as well tabletop exercises and pen test reviews. It will also cover system acquisition and maintenance controls, vulnerability management, and assisting DCDE with coordinated vulnerability disclosure.

AI analysis updated 3 weeks, 1 day ago

Bid ↗
Details

Value

€1.4m

Deadline

27 Aug

View on eTenders ↗

Location

Not specified.

Procedure

Open

Clarification

11 Aug 2026

eTenders ID

8732511

✦ Ask AI about this tender

Ask AI

Knows this tender's documents

Is this a good fit for us?
Based on the deadline, buyer, and eligibility requirements in the tender documents, here's a quick read on fit — with citations back to the exact clause 1 so you can verify it yourself.

Example only — sign up to ask about this tender