Request for Tender for the Provision of Chief Information Security Officer (CISO) as a Service and Associated Cyber Security Advisory and Specialist Support Services
Value
€500k
Deadline
04 Aug
04 Aug 2026
Value
€500k
Deadline
04 Aug
Provision of CISO advisory and specialist cyber security support services for Coimisiún na Meán, split into core ICT and broader business unit support.
CISO as a Service and Cyber Security Advisory for Coimisiún na Meán
Bidder profile
Firms with established expertise in providing CISO as a Service and comprehensive cyber security advisory, particularly those with experience serving public sector or regulated entities and meeting high insurance and turnover requirements.
Risks & flags
- High insurance requirements
- Significant turnover requirement
- Extensive prior experience needed
- Specific personnel experience requirements
Briefing
AI-generated analysis of the documents. Check the official notice and any amendments for current submission details.
1. At a glance
| Buyer | Coimisiún na Meán |
|---|---|
| Title | Request for Tender for the Provision of Chief Information Security Officer (CISO) as a Service and Associated Cyber Security Advisory and Specialist Support Services |
| CPV / category | Not specified |
| Estimated value | €500,000 (excluding VAT) |
| Per-year | Not specified (maximum €50,000 per annum for Part 1, €50,000 per annum for Part 2) |
| Procedure type | Open Procedure |
| Lots | Not specified |
| Location | Ireland |
| Contract length | 3 years, with option to extend for up to two additional 12-month periods (max 5 years) |
| Submission deadline | 2026-08-04T15:00:00+00:00 |
| Go-live / start | Not specified |
2. Scope of Work
The contract requires the provision of Chief Information Security Officer (CISO) advisory services, alongside associated cyber security advisory and specialist support services for Coimisiún na Meán. The services are divided into two primary components.
Part 1 focuses on CISO advisory services and ICT-focused cyber security advisory support for Coimisiún na Meán's ICT team. This includes expert guidance, advice, and support concerning information security governance, cyber security risk management, and ICT policies, procedures, processes, and technical controls. The successful tenderer will assist Coimisiún na Meán in aligning its ICT environment, information security arrangements, and cyber security practices with applicable public sector requirements, industry best practices, and standards such as ISO/IEC 27001. Annual expenditure for Part 1 is capped at €50,000 excluding VAT.
Part 2 involves specialist cyber security advisory and support services for business units outside of core ICT operational activities. These services aim to support Coimisiún na Meán in meeting broader statutory, regulatory, and operational obligations across its functions and regulatory remit. These services are optional and will be procured on a drawdown basis as required. Annual expenditure for Part 2 is not expected to exceed €50,000 excluding VAT.
The contract will commence upon execution and has an initial term of three years. Coimisiún na Meán reserves the right to extend the contract for up to two additional 12-month periods, bringing the maximum possible duration to five years. The estimated maximum value of the contract is €500,000 excluding VAT over the entire term.
3. Background & buyer context
Coimisiún na Meán was established as an independent regulator to oversee and enforce new and updated regulatory frameworks for demand-driven audiovisual media services and online safety, as set out in the Online Safety and Media Regulation Act. The Commission plays a key role in the development and funding of the wider media sector, including devising and implementing a Media Fund. It also advises the Minister on the creation of a European Works Levy and supports equality, diversity, inclusion, and sustainability within the media sector. The Commission is structured as a multi-person body, initially led by three Commissioners and an Executive Chairperson. This procurement is driven by the significantly expanded regulatory framework and the need for robust information security governance and cyber security support to fulfil its mandate.
4. Eligibility & selection criteria
Bidders must meet the following minimum requirements to be considered:
- Turnover requirement: Tenderers must have achieved a minimum average annual turnover of €2,500,000 over the previous three financial years. If established for a shorter period, this requirement must be met for each year of trading.
- Insurance:
- Employers Liability Insurance: €13 million
- Public Liability Insurance: €6.5 million
- Professional Indemnity Insurance: €1 million Evidence of these insurances, or the ability to put them in place, is required.
- Certifications: Tenderers must hold valid certification to ISO 27001 or an equivalent independently certified information security management standard.
- Past experience: Tenderers must have successfully completed at least three contracts of a similar nature, scale, and complexity within the previous five years. These contracts should involve cyber security advisory, governance, assurance, CISO advisory services, or related specialist cyber security support delivered to public sector bodies, regulated entities, or similarly complex organisations.
- Personnel: The proposed Technical Liaison / Lead CISO resource must have a minimum of 10 years' relevant experience. Specific roles mentioned with minimum experience requirements include:
- Security Auditor / Compliance Specialist: Minimum 5 years' relevant experience.
- Penetration Tester: Minimum 5 years' relevant experience and relevant CREST, CHECK, or equivalent certification.
- Digital Forensics Specialist: Minimum 5 years' relevant experience.
- Governance, Risk and Compliance Specialist: Minimum 5 years' relevant experience.
- Data Protection Officer: Minimum 5 years' relevant experience.
- Security Architect: Minimum 5 years' relevant experience. CVs demonstrating expertise for proposed roles are mandatory.
- Geographic / facility constraints: While not a strict geographic constraint, the tender requires confirmation of the ability to attend in-person meetings in Ireland. Support services are expected between 08:00 and 18:00 Monday to Friday, with escalation support available outside these hours.
5. Award criteria & scoring
The contract will be awarded to the Tenderer submitting the Most Economically Advantageous Tender (MEAT). The evaluation will consider the tenderer's understanding of the requirements, proposed methodology, service delivery model, resources, relevant experience, governance arrangements, pricing structure, and approach to environmental, social, and sustainability considerations.
Criterion Weight (%) Minimum score required Sub-criteria
Can you bid?
Required certifications
- ISO 27001
Minimum turnover
€2,500,000
Public liability insurance
€6,500,000
Professional indemnity insurance
€1,000,000
Named standards / methodologies
Scoring
Most Economically Advantageous Tender
Documents (7)
RFT_CnaM_CISO as a Service_July 2026.pdf
333.8 KB · RFT / Invitation to Tender
CnaM Pricing Schedule_CISO_July 2026.xlsx
41.8 KB · Pricing / BOQ / Schedule of Rates
OGP services-confidentiality-agreement-July 2026.docx
56.7 KB · Contract / Agreement / Terms
services-contract-CISO_July 2026.pdf
402.1 KB · Contract / Agreement / Terms
Clarifications 1 - CISO.pdf
144.3 KB · Clarification / Addendum
Clarifications 2 - CISO.pdf
113.9 KB · Clarification / Addendum
CnaM TRD July 2026.docx
160.1 KB
Original notice text
The Commission is seeking the provision of Chief Information Security Officer (CISO) Advisory Service and associated cyber security advisory and specialist support services. The Services will comprise two primary components: Part 1 – CISO Advisory Service and ICT Cyber Security Services The first component of the Services relates to the provision of CISO Advisory Service and ICT-focused cyber security advisory support to An Coimisiún’s ICT team. This will include the provision of expert guidance, advice and support in respect of information security governance, cyber security risk management, ICT policies, procedures, processes and technical controls. The successful Tenderer will be required to support An Coimisiún in ensuring that its ICT environment, information security arrangements and cyber security practices are aligned with applicable public sector requirements, recognised industry best practice and relevant standards, including ISO/IEC 27001. Part 2 – Non-ICT Cyber Security Support Services The second component of the Services relates to the provision of specialist cyber security advisory and support services to business units across An Coimisiún outside of core ICT operational activities. These Services are intended to support An Coimisiún in meeting broader statutory, regulatory and operational obligations arising across its functions and regulatory remit. The Contract shall commence on the date of contract execution and shall continue for an initial period of three (3) years. The Commission reserves the right, at its sole discretion, to extend the Contract for up to two (2) further periods of twelve (12) months each, subject to satisfactory performance, continued business requirements and the availability of funding. More detail available in supporting documents.
AI analysis updated 1 month, 2 weeks ago
Value
€500k
Deadline
04 Aug
Buyer
Coimisiún na MeánLocation
Ireland
Procedure
Open
Clarification
04 Aug 2026
eTenders ID
8553401
Ask AI
Knows this tender's documents
Example only — sign up to ask about this tender