Skip to content
TenderMatch
The recorded submission deadline has passed. Find open opportunities. Check the official notice for amendments.
← Tenders / NIS2 Operational Readiness Cyber Consultancy
Closed Professional Consultancy Services SME Suitable Open

NIS2 Operational Readiness Cyber Consultancy

Value

€180k

Deadline

28 Aug

HPRA requires consultancy to develop cyber security inspection methodologies and operational readiness for NIS2 compliance.

SME fit: High Bid effort: High

HPRA seeks cyber security consultancy for NIS2 operational readiness

Bidder profile

SMEs with specialised expertise in cyber security regulatory compliance, inspection methodology development, and experience in regulated sectors.

Risks & flags

  • Short contract duration (3 months)
  • Tight timeline for tender submission
  • High insurance requirements
  • Potential for award to runner-up

Briefing

AI-generated analysis of the documents. Check the official notice and any amendments for current submission details.

1. At a glance

Buyer Health Products Regulatory Authority
Title NIS2 Operational Readiness Cyber Consultancy
CPV / category Not specified
Estimated value €180,000
Per-year (if multi-year) Not specified
Procedure type Single Stage Procedure
Lots Not specified
Location Ireland
Contract length 3 months
Submission deadline 2026-08-28T11:00:00+00:00
Go-live / start Mid-late September (anticipated)

2. Scope of Work

This tender seeks specialist cyber security consultancy services to support the Health Products Regulatory Authority (HPRA) in its preparation for anticipated designation as a competent authority under the National Cyber Security Bill, transposing the NIS2 Directive. The estimated value for this 3-month contract is €180,000. The successful bidder will form the 'Cyber Workstream' within the HPRA's NIS2 Operational Readiness Programme. The focus is on developing the HPRA's operational readiness for conducting cyber security inspections, not on assessing the HPRA's own compliance or performing inspections.

The required services and deliverables include:

  • Cyber Security Inspection Methodology: Development of a documented methodology for planning, conducting, and concluding inspections, differentiating between Essential and Important Entities. The approach must prioritise efficiency and well-evidenced conclusions.
  • Risk-Based Approach: Creation of a documented approach for selecting entities for inspection and determining inspection timing, including prioritisation criteria and escalation triggers.
  • Maturity Assessment: Preparation of a maturity assessment for in-scope entities to evaluate their cyber posture, informing the risk-based assessment and aligning with the inspection methodology.
  • Evidence Request List: Development of a structured list detailing the information, documents, and evidence of implementation required from entities during inspections.
  • Inspection Assessment Template: Creation of a template with evaluation criteria for inspectors to systematically assess entity compliance with the Cyber Security Bill and relevant guidelines.
  • FAQ Material for HPRA Website: Preparation of frequently asked questions for the HPRA website concerning NIS2 obligations, the inspection process, and non-compliance consequences.
  • Training / Knowledge Sharing: Delivery of training to designated Authorised Officers and other relevant HPRA stakeholders on the developed inspection methodologies and deliverables.

The tenderer must propose a single senior individual or a small team, such as a lead cyber security specialist supported by part-time senior oversight. Deliverables will be reviewed internally by the HPRA. The tenderer must be able to perform detailed walkthroughs of all outputs, demonstrating how they meet regulatory obligations pragmatically. A detailed plan of work with clear deliverables and associated timeframes is required, with weekly tracking within the programme.

3. Background & buyer context

The Health Products Regulatory Authority (HPRA) is the Irish statutory body responsible for regulating medicines, medical devices, and healthcare products to protect and enhance public and animal health. It operates as a self-funded agency, with 85% of its income derived from industry fees and 15% from government grants.

This procurement is driven by the HPRA's anticipated designation as a competent authority for specific health sector entities under the forthcoming National Cyber Security Bill, which transposes the EU's NIS2 Directive into Irish law. The HPRA's remit is expected to cover entities manufacturing basic pharmaceutical products and critical medical devices. Approximately 200 entities are in scope, with 15-20% classified as Essential and the remainder as Important.

The HPRA has established a central NIS2 project management office (PMO) to manage this preparatory phase. This tender specifically seeks cyber security consultancy to support the HPRA in becoming operationally ready to conduct cyber security inspections once the Bill is enacted and designations are conferred. The incumbent for these specific consultancy services is not named.

4. Eligibility & selection criteria

  • Turnover requirement: Not specified for this tender.
  • Insurance:
  • Employers Liability: €12.7 million
  • Public Liability: €2.6 million
  • Professional Indemnity: €500k
  • Cyber Security: €2 million
  • Certifications: Not specified for this tender.
  • Past experience: Tenderers must demonstrate relevant expertise and experience in:
  • Cyber security regulatory frameworks.
  • Inspection or audit methodologies.
  • Risk-based supervision.
  • Maturity assessment.
  • Evidence assessment.
  • Projects delivered within regulated environments, preferably in the health sector or other regulated sectors subject to cyber security obligations.
  • Personnel: The proposed team must have demonstrable expertise in cyber security, regulatory compliance, inspection/audit design, risk assessment, and stakeholder engagement. Specific roles are not mandated, but the proposed team structure must provide equivalent delivery capacity, continuity, senior accountability, and quality assurance.
  • Geographic / facility constraints: Not specified for this tender.

5. Award criteria & scoring

Criterion Weighting Maximum Marks Minimum Marks
A: Price (excluding VAT) 30% 3000 N/A
B: Relevant Experience, Proposed Team, Planned Approach and Delivery Capacity 40% 4000 2000 (50% of criterion marks)
C: Information Security, Confidentiality and Data Handling 20% 2000 1000 (50% of criterion marks)
D: Contract and relationship management 10% 1000 500 (50% of criterion marks)

The contract will be awarded on the basis of the Most Economically Advantageous Tender (MEAT). A minimum score of 50% is required for criteria B, C, and D. The lowest price tender that meets all minimum qualitative award criteria will receive maximum marks for price.

6. Submission requirements

  • Method statement / response document: Tenderers must use the provided Tender Response Document (TRD). Responses should be structured to follow the RFT's numbering where possible, include page numbers, a contents page, and be formatted for ease of evaluation.
  • CVs: Not explicitly mentioned with page limits, but proposed team members' qualifications, experience, and availability must be detailed.
  • Pricing schedule: Must be completed using the TRD, providing daily rates (excluding VAT) for proposed resources. A breakdown of costs per meeting is required.
  • Case studies: Not explicitly mentioned with number or value range requirements, but examples of comparable assignments and client references/testimonials are required.
  • Declarations:
  • Declaration of Bona Fides (Article 57 of Directive 2014/24/EU).
  • Declaration regarding compliance with relevant statutory obligations.
  • Confirmation of tax compliance.
  • Confirmation of financial standing (evidence required prior to award).
  • Confirmation of required insurances.
  • Disclosure of any conflicts of interest.
  • Mandatory site visit: Not specified for this tender.
  • Submission portal: Tenders must be submitted electronically via the eTenders post-box facility on www.etenders.gov.ie only.

7. Key dates & process

Event Date
RFT issued 07/08/2026
Clarification deadline 21/08/2026 12 Noon
Tender deadline 28/08/2026 11:00
Expected award Not specified
Contract start Mid-late September (anticipated)
Go-live / mobilisation Not specified

The tender validity period is 12 months from the closing date for tender receipt.

8. Contract terms that matter

  • Term + extension: The contract is for an initial term of 3 months. The HPRA reserves the right to extend the term for periods of up to 3 months, with a maximum of two such extensions.
  • Payment terms: Not specified in detail, but invoices are deemed accepted if no queries are raised within 14 days.
  • Key SLAs/KPIs: Not specified. Performance will be assessed against the deliverables and the contract management requirements.
  • Liquidated damages or penalty regimes: Not specified.
  • Termination clauses: Either party may terminate with 14 days' notice if a breach is not remedied within 30 days of a written request.
  • IP ownership: Not specified.
  • Sub-contracting rules: Tenderers must indicate the nature of any outsourced services and the identity of any third parties used.
  • Parent-company guarantee or bond requirements: Not specified.

9. Risks, red flags & unusuals

  • Short contract duration: The 3-month term is unusually short for developing comprehensive methodologies and training materials, suggesting a need for highly focused and efficient delivery.
  • Tight timeline: The period between RFT issuance (August 7th) and the tender deadline (August 28th) is compressed, requiring prompt bidder engagement.
  • High insurance requirements: The specified insurance levels, particularly Public Liability (€2.6m) and Cyber Security (€2m), are substantial for a consultancy project of this estimated value, potentially filtering out smaller firms.
  • No budget disclosure: The estimated value of €180,000 for a 3-month engagement is provided, but no detailed budget breakdown or expected daily rates are published, requiring bidders to propose their own pricing structure.
  • Potential for award to runner-up: The contract may be awarded to the next highest scoring tenderer if the successful bidder cannot deliver.

10. SME fit assessment

This tender is likely best suited for small to medium-sized enterprises (SMEs) with specialised expertise in cyber security regulatory compliance and inspection methodology development. A credible bidder would typically be a consultancy firm with a proven track record in advising regulatory bodies or organisations in highly regulated sectors on cyber security frameworks.

  • Who can credibly bid: Firms with demonstrable experience in developing inspection frameworks, risk assessment methodologies, and maturity models, particularly within regulated environments like healthcare or pharmaceuticals. The proposed team should include at least one senior cyber security specialist with significant experience.
  • Consortium or sub-contracting: Consortium bids are permitted, and tenderers must declare any sub-contracting. This allows SMEs to partner to meet requirements.
  • Indicative bid-prep effort: Significant effort is required. Bidders need to develop a detailed methodology, propose a team structure with CVs, outline their approach to information security, and complete the TRD, including a pricing schedule. This could require 5-10 days of dedicated effort for a well-prepared bid.
  • Pwin signal: The tender is open, with no named incumbent for this specific consultancy. The MEAT award criteria, with a significant weighting on qualitative aspects (70%), suggests that the quality of the proposed approach, team, and experience will be critical. The relatively low estimated value for the required expertise might deter very large consultancies, potentially favouring specialised SMEs.

11. Where to dig deeper

  • Source RFT filename: RFT NIS 2_HPRA Operational Readiness_Cyber Consultancy (1).docx
  • eTenders CFT ID: Not specified in the provided text.
  • Contact email or clarification portal: eTenders messaging facility on www.etenders.gov.ie
  • Most important attachments:
  • Tender Response Document (TRD)
  • Draft Contract Terms and Conditions
  • Pricing Schedule Template

Can you bid?

Public liability insurance

€2,600,000

Professional indemnity insurance

€500,000

Scoring

Most Economically Advantageous Tender

Documents (3)

DOCX

RFT NIS 2_HPRA Operational Readiness_Cyber Consultancy (1).docx

252.7 KB · RFT / Invitation to Tender

DOCX

OGP contract for Cyber Security Consultancy Services - to support the HPRA’s NIS 2 Inspection Readiness Programme.docx

91.5 KB · Contract / Agreement / Terms

DOCX

Tender-Response-Document_NIS2 Operational Readiness Cyber Consultant.docx

99.2 KB

Original notice text

This RFT is for the provision of specialist cyber security consultancy services to support the HPRA to become operationally ready to undertake cyber security inspections once the Bill is enacted and the associated designations are conferred.

AI analysis updated 3 weeks ago

Bid ↗
Details

Value

€180k

Deadline

28 Aug

View on eTenders ↗

Location

Ireland

Procedure

Open

Clarification

21 Aug 2026

eTenders ID

8807645

✦ Ask AI about this tender

Ask AI

Knows this tender's documents

Is this a good fit for us?
Based on the deadline, buyer, and eligibility requirements in the tender documents, here's a quick read on fit — with citations back to the exact clause 1 so you can verify it yourself.

Example only — sign up to ask about this tender