ComReg T21616 - IT Security Consultancy Services
Deadline
16 Jun
16 Jun 2026
Deadline
16 Jun
IT Security Consultancy Services for ComReg over a potential 3-year period
IT Security Consultancy Services for ComReg over a potential 3-year period
Bidder profile
Medium-sized enterprises with a strong IT security focus and ISO 27001 certification. Suitable for consortium bids.
Risks & flags
- High turnover requirement
- ISO 27001 certification needed
- Lack of detailed KPIs and SLAs
Briefing
AI-generated analysis of the documents. Check the official notice and any amendments for current submission details.
1. At a glance
| Buyer | Commission for Communications Regulation (ComReg) |
|---|---|
| Title | ComReg T21616 - IT Security Consultancy Services |
| CPV / category | Not stated |
| Estimated value | Not disclosed |
| Per-year | Not stated |
| Procedure type | Open procedure |
| Lots | Not used |
| Location | Not stated |
| Contract length | 1 year, with up to 2 extensions of 12 months each |
| Submission deadline | 09 June 2026, 12:00 Noon |
| Go-live / start | Early July 2026 |
2. Scope of Work
The tender involves providing IT Security Consultancy Services to ComReg. The contractor will assist ComReg in enhancing its IT security posture. The scope includes:
- Security Assessments: Conduct regular security assessments and audits to identify vulnerabilities within ComReg's IT infrastructure.
- Compliance Support: Ensure compliance with ISO 27001, NIS2, and CIS Controls or equivalent security frameworks.
- Incident Response: Develop and implement incident response strategies and procedures.
- Risk Management: Identify, assess, and mitigate IT security risks.
- Policy Development: Assist in the development and updating of IT security policies and procedures.
- Training and Awareness: Provide training sessions to ComReg staff on IT security best practices.
- Reporting: Prepare detailed reports on security assessments, incidents, and compliance status.
- Consultation: Offer expert advice on IT security matters as required by ComReg.
The contractor will work closely with ComReg's internal IT team and may be required to engage with external stakeholders. The services are expected to be delivered primarily at ComReg's premises, with some remote work possible.
3. Background & buyer context
ComReg is procuring IT Security Consultancy Services to bolster its cybersecurity framework in response to evolving threats and regulatory requirements. This procurement aligns with ComReg's strategic objective to maintain robust IT security measures. The initiative is part of a broader effort to ensure compliance with national and EU regulations, including the General Data Protection Regulation (GDPR). The incumbent provider, if any, is not named in the tender documents. The procurement reflects ComReg's commitment to safeguarding its IT infrastructure and data integrity.
4. Eligibility & selection criteria
- Turnover requirement: Minimum annual turnover of €800,000 for each of the last 3 financial years.
- Insurance:
- Public Liability: €6,500,000 per claim.
- Employer's Liability: €13,000,000 per claim.
- Professional Indemnity: €1,000,000 per claim.
- Cyber Liability: €5,000,000 per occurrence.
- Certifications: ISO 27001 certification required.
- Past experience: Not specified for this tender.
- Personnel: Not specified for this tender.
- Geographic / facility constraints: Not specified for this tender.
5. Award criteria & scoring
| Criterion | Weight (%) | Sub-criteria | Pass/fail thresholds |
|---|---|---|---|
| Quality of Proposal | 70% | Methodology, Experience, Compliance | Not specified |
| Pricing | 30% | Cost-effectiveness | Not specified |
The evaluation follows the Most Economically Advantageous Tender (MEAT) approach, with a 70/30 quality/price split.
6. Submission requirements
- Method statement / response document: No named template, no page limits specified.
- CVs: Not specified for named roles.
- Pricing schedule: Appendix 2 format.
- Case studies: Not specified.
- Declarations: ESPD, Tax clearance, Conflict of Interest.
- Mandatory site visit: Not specified.
- Submission portal: eTenders, with specific format rules (single ZIP file, max 500MB).
7. Key dates & process
| Event | Date |
|---|---|
| RFT issued | 08 May 2026 |
| Clarification deadline | 22 May 2026, 17:00 |
| Tender deadline | 09 June 2026, 12:00 Noon |
| Expected award | End June 2026 |
| Contract start | Early July 2026 |
| Go-live / mobilisation | July 2026 |
8. Contract terms that matter
The contract is for 1 year, with the possibility of two 12-month extensions. Payment terms require settlement within 15 days of invoice receipt. Key performance indicators (KPIs) and service level agreements (SLAs) are not detailed. Liquidated damages or penalty regimes are not specified. Intellectual property rights remain with ComReg. Sub-contracting is allowed, but changes post-award require ComReg's approval. No parent-company guarantee or bond is required.
9. Risks, red flags & unusuals
The tender specifies a high turnover requirement relative to the estimated contract value, potentially limiting the bidder pool. The requirement for ISO 27001 certification may exclude smaller firms lacking this accreditation. The absence of detailed KPIs and SLAs could lead to ambiguity in performance expectations. The contract's dependency on compliance with evolving EU regulations introduces potential scope changes.
10. SME fit assessment
This tender is suitable for medium-sized enterprises with a strong IT security focus and ISO 27001 certification. Smaller firms may find the turnover and certification requirements challenging. Consortium bids are allowed, offering opportunities for SMEs to partner with larger firms. Bid preparation is likely to require several days, given the need for detailed compliance documentation. The presence of an incumbent is not confirmed, but the high turnover requirement suggests a competitive environment.
11. Where to dig deeper
- Source RFT filename: "Request For Tender - IT Security Consultancy Service (Non-Framework).pdf"
- eTenders CFT ID: Not specified
- Contact email or clarification portal: eTenders messaging facility
- Important attachments:
- Appendix 1 — Requirements and Specifications
- Appendix 2 — Pricing Schedule
- Appendix 4 — European Single Procurement Document (eESPD)
Can you bid?
Required certifications
- ISO 27001
Minimum turnover
€800,000
Public liability insurance
€6,500,000
Professional indemnity insurance
€1,000,000
Named standards / methodologies
Scoring
Most Economically Advantageous Tender
Documents (13)
Request For Tender - IT Security Consultancy Service (Non-Framework).docx
217.6 KB · RFT / Invitation to Tender
Request For Tender - IT Security Consultancy Service (Non-Framework).pdf
659.2 KB · RFT / Invitation to Tender
ComReg T21616 IT Security Consultancy Services Contract.docx
173.6 KB · Contract / Agreement / Terms
ESPD Sample for T21616.docx
90.1 KB · ESPD (European Single Procurement Document)
T21616 - Clarification Response (001).docx
24.2 KB · Clarification / Addendum
T21616 - Clarification Response (002).docx
23.9 KB · Clarification / Addendum
T21616 - Clarification Response (003).docx
26.9 KB · Clarification / Addendum
T21616 - Clarification Response (004).docx
23.8 KB · Clarification / Addendum
T21616 - Clarification Response (005).docx
25.1 KB · Clarification / Addendum
T21616 - Clarification Response (006).docx
25.8 KB · Clarification / Addendum
T21616 - Clarification Response (007).docx
24.3 KB · Clarification / Addendum
T21616 - Clarification Response (008).docx
23.7 KB · Clarification / Addendum
T21616 - Clarification Response (009).docx
26.5 KB · Clarification / Addendum
Original notice text
ComReg T21616 - Request for Tender (RFT) for the provision of IT Security Consultancy Services (Please refer to all tender documentation attached to this competition notice, in order to complete tender application)
AI analysis updated 2 months, 2 weeks ago
Deadline
16 Jun
Location
Primarily at ComReg's premises with some remote work possible.
Procedure
Open
Clarification
22 May 2026
eTenders ID
8098942
Ask AI
Knows this tender's documents
Example only — sign up to ask about this tender