NIS2 Operational Readiness Cyber Consultancy
Value
€180k
Deadline
28 Aug
28 Aug 2026
Value
€180k
Deadline
28 Aug
HPRA requires consultancy to develop cyber security inspection methodologies and operational readiness for NIS2 compliance.
HPRA seeks cyber security consultancy for NIS2 operational readiness
Bidder profile
SMEs with specialised expertise in cyber security regulatory compliance, inspection methodology development, and experience in regulated sectors.
Risks & flags
- Short contract duration (3 months)
- Tight timeline for tender submission
- High insurance requirements
- Potential for award to runner-up
Briefing
AI-generated analysis of the documents. Check the official notice and any amendments for current submission details.
1. At a glance
| Buyer | Health Products Regulatory Authority |
|---|---|
| Title | NIS2 Operational Readiness Cyber Consultancy |
| CPV / category | Not specified |
| Estimated value | €180,000 |
| Per-year (if multi-year) | Not specified |
| Procedure type | Single Stage Procedure |
| Lots | Not specified |
| Location | Ireland |
| Contract length | 3 months |
| Submission deadline | 2026-08-28T11:00:00+00:00 |
| Go-live / start | Mid-late September (anticipated) |
2. Scope of Work
This tender seeks specialist cyber security consultancy services to support the Health Products Regulatory Authority (HPRA) in its preparation for anticipated designation as a competent authority under the National Cyber Security Bill, transposing the NIS2 Directive. The estimated value for this 3-month contract is €180,000. The successful bidder will form the 'Cyber Workstream' within the HPRA's NIS2 Operational Readiness Programme. The focus is on developing the HPRA's operational readiness for conducting cyber security inspections, not on assessing the HPRA's own compliance or performing inspections.
The required services and deliverables include:
- Cyber Security Inspection Methodology: Development of a documented methodology for planning, conducting, and concluding inspections, differentiating between Essential and Important Entities. The approach must prioritise efficiency and well-evidenced conclusions.
- Risk-Based Approach: Creation of a documented approach for selecting entities for inspection and determining inspection timing, including prioritisation criteria and escalation triggers.
- Maturity Assessment: Preparation of a maturity assessment for in-scope entities to evaluate their cyber posture, informing the risk-based assessment and aligning with the inspection methodology.
- Evidence Request List: Development of a structured list detailing the information, documents, and evidence of implementation required from entities during inspections.
- Inspection Assessment Template: Creation of a template with evaluation criteria for inspectors to systematically assess entity compliance with the Cyber Security Bill and relevant guidelines.
- FAQ Material for HPRA Website: Preparation of frequently asked questions for the HPRA website concerning NIS2 obligations, the inspection process, and non-compliance consequences.
- Training / Knowledge Sharing: Delivery of training to designated Authorised Officers and other relevant HPRA stakeholders on the developed inspection methodologies and deliverables.
The tenderer must propose a single senior individual or a small team, such as a lead cyber security specialist supported by part-time senior oversight. Deliverables will be reviewed internally by the HPRA. The tenderer must be able to perform detailed walkthroughs of all outputs, demonstrating how they meet regulatory obligations pragmatically. A detailed plan of work with clear deliverables and associated timeframes is required, with weekly tracking within the programme.
3. Background & buyer context
The Health Products Regulatory Authority (HPRA) is the Irish statutory body responsible for regulating medicines, medical devices, and healthcare products to protect and enhance public and animal health. It operates as a self-funded agency, with 85% of its income derived from industry fees and 15% from government grants.
This procurement is driven by the HPRA's anticipated designation as a competent authority for specific health sector entities under the forthcoming National Cyber Security Bill, which transposes the EU's NIS2 Directive into Irish law. The HPRA's remit is expected to cover entities manufacturing basic pharmaceutical products and critical medical devices. Approximately 200 entities are in scope, with 15-20% classified as Essential and the remainder as Important.
The HPRA has established a central NIS2 project management office (PMO) to manage this preparatory phase. This tender specifically seeks cyber security consultancy to support the HPRA in becoming operationally ready to conduct cyber security inspections once the Bill is enacted and designations are conferred. The incumbent for these specific consultancy services is not named.
4. Eligibility & selection criteria
- Turnover requirement: Not specified for this tender.
- Insurance:
- Employers Liability: €12.7 million
- Public Liability: €2.6 million
- Professional Indemnity: €500k
- Cyber Security: €2 million
- Certifications: Not specified for this tender.
- Past experience: Tenderers must demonstrate relevant expertise and experience in:
- Cyber security regulatory frameworks.
- Inspection or audit methodologies.
- Risk-based supervision.
- Maturity assessment.
- Evidence assessment.
- Projects delivered within regulated environments, preferably in the health sector or other regulated sectors subject to cyber security obligations.
- Personnel: The proposed team must have demonstrable expertise in cyber security, regulatory compliance, inspection/audit design, risk assessment, and stakeholder engagement. Specific roles are not mandated, but the proposed team structure must provide equivalent delivery capacity, continuity, senior accountability, and quality assurance.
- Geographic / facility constraints: Not specified for this tender.
5. Award criteria & scoring
| Criterion | Weighting | Maximum Marks | Minimum Marks |
|---|---|---|---|
| A: Price (excluding VAT) | 30% | 3000 | N/A |
| B: Relevant Experience, Proposed Team, Planned Approach and Delivery Capacity | 40% | 4000 | 2000 (50% of criterion marks) |
| C: Information Security, Confidentiality and Data Handling | 20% | 2000 | 1000 (50% of criterion marks) |
| D: Contract and relationship management | 10% | 1000 | 500 (50% of criterion marks) |
The contract will be awarded on the basis of the Most Economically Advantageous Tender (MEAT). A minimum score of 50% is required for criteria B, C, and D. The lowest price tender that meets all minimum qualitative award criteria will receive maximum marks for price.
6. Submission requirements
- Method statement / response document: Tenderers must use the provided Tender Response Document (TRD). Responses should be structured to follow the RFT's numbering where possible, include page numbers, a contents page, and be formatted for ease of evaluation.
- CVs: Not explicitly mentioned with page limits, but proposed team members' qualifications, experience, and availability must be detailed.
- Pricing schedule: Must be completed using the TRD, providing daily rates (excluding VAT) for proposed resources. A breakdown of costs per meeting is required.
- Case studies: Not explicitly mentioned with number or value range requirements, but examples of comparable assignments and client references/testimonials are required.
- Declarations:
- Declaration of Bona Fides (Article 57 of Directive 2014/24/EU).
- Declaration regarding compliance with relevant statutory obligations.
- Confirmation of tax compliance.
- Confirmation of financial standing (evidence required prior to award).
- Confirmation of required insurances.
- Disclosure of any conflicts of interest.
- Mandatory site visit: Not specified for this tender.
- Submission portal: Tenders must be submitted electronically via the eTenders post-box facility on www.etenders.gov.ie only.
7. Key dates & process
| Event | Date |
|---|---|
| RFT issued | 07/08/2026 |
| Clarification deadline | 21/08/2026 12 Noon |
| Tender deadline | 28/08/2026 11:00 |
| Expected award | Not specified |
| Contract start | Mid-late September (anticipated) |
| Go-live / mobilisation | Not specified |
The tender validity period is 12 months from the closing date for tender receipt.
8. Contract terms that matter
- Term + extension: The contract is for an initial term of 3 months. The HPRA reserves the right to extend the term for periods of up to 3 months, with a maximum of two such extensions.
- Payment terms: Not specified in detail, but invoices are deemed accepted if no queries are raised within 14 days.
- Key SLAs/KPIs: Not specified. Performance will be assessed against the deliverables and the contract management requirements.
- Liquidated damages or penalty regimes: Not specified.
- Termination clauses: Either party may terminate with 14 days' notice if a breach is not remedied within 30 days of a written request.
- IP ownership: Not specified.
- Sub-contracting rules: Tenderers must indicate the nature of any outsourced services and the identity of any third parties used.
- Parent-company guarantee or bond requirements: Not specified.
9. Risks, red flags & unusuals
- Short contract duration: The 3-month term is unusually short for developing comprehensive methodologies and training materials, suggesting a need for highly focused and efficient delivery.
- Tight timeline: The period between RFT issuance (August 7th) and the tender deadline (August 28th) is compressed, requiring prompt bidder engagement.
- High insurance requirements: The specified insurance levels, particularly Public Liability (€2.6m) and Cyber Security (€2m), are substantial for a consultancy project of this estimated value, potentially filtering out smaller firms.
- No budget disclosure: The estimated value of €180,000 for a 3-month engagement is provided, but no detailed budget breakdown or expected daily rates are published, requiring bidders to propose their own pricing structure.
- Potential for award to runner-up: The contract may be awarded to the next highest scoring tenderer if the successful bidder cannot deliver.
10. SME fit assessment
This tender is likely best suited for small to medium-sized enterprises (SMEs) with specialised expertise in cyber security regulatory compliance and inspection methodology development. A credible bidder would typically be a consultancy firm with a proven track record in advising regulatory bodies or organisations in highly regulated sectors on cyber security frameworks.
- Who can credibly bid: Firms with demonstrable experience in developing inspection frameworks, risk assessment methodologies, and maturity models, particularly within regulated environments like healthcare or pharmaceuticals. The proposed team should include at least one senior cyber security specialist with significant experience.
- Consortium or sub-contracting: Consortium bids are permitted, and tenderers must declare any sub-contracting. This allows SMEs to partner to meet requirements.
- Indicative bid-prep effort: Significant effort is required. Bidders need to develop a detailed methodology, propose a team structure with CVs, outline their approach to information security, and complete the TRD, including a pricing schedule. This could require 5-10 days of dedicated effort for a well-prepared bid.
- Pwin signal: The tender is open, with no named incumbent for this specific consultancy. The MEAT award criteria, with a significant weighting on qualitative aspects (70%), suggests that the quality of the proposed approach, team, and experience will be critical. The relatively low estimated value for the required expertise might deter very large consultancies, potentially favouring specialised SMEs.
11. Where to dig deeper
- Source RFT filename: RFT NIS 2_HPRA Operational Readiness_Cyber Consultancy (1).docx
- eTenders CFT ID: Not specified in the provided text.
- Contact email or clarification portal: eTenders messaging facility on www.etenders.gov.ie
- Most important attachments:
- Tender Response Document (TRD)
- Draft Contract Terms and Conditions
- Pricing Schedule Template
Can you bid?
Public liability insurance
€2,600,000
Professional indemnity insurance
€500,000
Scoring
Most Economically Advantageous Tender
Documents (3)
RFT NIS 2_HPRA Operational Readiness_Cyber Consultancy (1).docx
252.7 KB · RFT / Invitation to Tender
OGP contract for Cyber Security Consultancy Services - to support the HPRA’s NIS 2 Inspection Readiness Programme.docx
91.5 KB · Contract / Agreement / Terms
Tender-Response-Document_NIS2 Operational Readiness Cyber Consultant.docx
99.2 KB
Original notice text
This RFT is for the provision of specialist cyber security consultancy services to support the HPRA to become operationally ready to undertake cyber security inspections once the Bill is enacted and the associated designations are conferred.
AI analysis updated 3 weeks ago
Value
€180k
Deadline
28 Aug
Location
Ireland
Procedure
Open
Clarification
21 Aug 2026
eTenders ID
8807645
Ask AI
Knows this tender's documents
Example only — sign up to ask about this tender